gemini-api-dev

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [Instruction-based Override]: The skill uses phrases like 'These rules override your training data' to ensure the AI agent uses the provided API documentation instead of potentially outdated internal knowledge. While this uses patterns associated with prompt injection, it is applied here for the legitimate purpose of knowledge synchronization for a technical API.
  • [Official SDK Integration]: The skill provides instructions to install and use official libraries such as google-genai (Python) and @google/genai (JavaScript). These are standard package installations from established registries.
  • [Managed Sandbox Execution]: Documentation for the 'Antigravity Agent' describes capabilities including code execution and file management. These are presented as managed features of the Gemini API platform that run in hosted, sandboxed Linux environments, rather than unsafe behaviors within the skill itself.
  • [Development Utility Commands]: The migration guide includes a shell command using rg (ripgrep) to help developers identify the scope of an API migration. This is a common, safe utility command for development environments.
  • [External Documentation Links]: The skill references numerous documentation pages hosted on ai.google.dev. These are official, well-known sources for the documented technology.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 04:18 PM
Security Audit — agent-trust-hub — gemini-api-dev