gemini-search

Warn

Audited by Socket on May 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core purpose is coherent, and the official Google Gemini CLI is a legitimate dependency, but the skill unnecessarily expands trust by requiring an unofficial third-party MCP bridge and broad Bash access. This creates medium supply-chain and credential-forwarding risk without evidence of confirmed malware.

Confidence: 87%Severity: 64%
Audit Metadata
Analyzed At
May 4, 2026, 10:30 AM
Package URL
pkg:socket/skills-sh/wanshuiyin%2FAuto-claude-code-research-in-sleep%2Fgemini-search%2F@f2fc8d4127ceec125631de1938bf3e6f8924395b