gemini-search
Warn
Audited by Socket on May 4, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core purpose is coherent, and the official Google Gemini CLI is a legitimate dependency, but the skill unnecessarily expands trust by requiring an unofficial third-party MCP bridge and broad Bash access. This creates medium supply-chain and credential-forwarding risk without evidence of confirmed malware.
Confidence: 87%Severity: 64%
Audit Metadata