gemini
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is broadly aligned with its stated purpose of using Gemini CLI, and the dependency provenance appears official, but it materially increases execution risk by steering the agent toward `--approval-mode yolo` for background use. This is not confirmed malware or credential theft, but it enables high-autonomy actions over the local codebase with reduced user oversight.
Confidence: 87%Severity: 59%
Audit Metadata