gemini-peer-review

Fail

Audited by Socket on Mar 1, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This skill is functionally coherent: it constructs prompts from local files and forwards them to the official Gemini (Generative Language) API using an API key supplied via GEMINI_API_KEY. There is no evidence of obfuscated or hidden malicious code, typosquatting domains, third-party proxying, or download-execute behaviors in the provided fragment. The main security concern is data exfiltration risk: the skill will send arbitrary project files (potentially containing secrets) to an external LLM service and persists the prompt to disk. Mitigations should include: explicit warnings to users about secrets, allow file filtering/whitelisting, automatic redaction of known secret patterns, secure file permissions for artifact files, and optionally an opt-in confirmation step before sending sensitive files. Overall, this appears to be a legitimate integration but with moderate risk of accidental sensitive-data exposure if used without care.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 1, 2026, 12:41 PM
Package URL
pkg:socket/skills-sh/jezweb%2Fclaude-skills%2Fgemini-peer-review%2F@342fec4c057f52e0d8ac7191926dc62bbdb7ba95