gemini

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is broadly aligned with its stated purpose of using Gemini CLI, and the dependency provenance appears official, but it materially increases execution risk by steering the agent toward `--approval-mode yolo` for background use. This is not confirmed malware or credential theft, but it enables high-autonomy actions over the local codebase with reduced user oversight.

Confidence: 87%Severity: 59%
Audit Metadata
Analyzed At
Sep 15, 2026, 12:53 AM
Package URL
pkg:socket/skills-sh/softaworks%2Fagent-toolkit%2Fgemini%2F@b652216e8eb2b51c94c78c1341ce466951b857e48f73a1c39e82a039d713e5ca
Security Audit — socket — gemini