omega-gemini-cli

Warn

Audited by Socket on Mar 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The Omega Gemini CLI skill is coherently aligned with its stated purpose: a headless Gemini-based analysis wrapper that accepts prompts (and embedded file content) and returns machine-readable JSON. It relies on an external Gemini CLI, which introduces standard supply-chain data-flow considerations (external service, OAuth flow, network use). There are no evident credential harvesting or malicious behaviors within the fragment itself; the risk is mainly data exposure to an external AI service and dependence on a third-party CLI. Overall, the design is plausible and proportionate to its stated purpose, with moderate security cautions around external data flow and data retention by the Gemini service.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 3, 2026, 08:45 AM
Package URL
pkg:socket/skills-sh/oimiragieo%2Fagent-studio%2Fomega-gemini-cli%2F@afa7c1f63f1844b127d33a42bd6c832e560b39f9