collaborating-with-gemini

Fail

Audited by Socket on Mar 7, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill presents a coherent and proportionate workflow for collaborative frontend design using the Gemini CLI. It relies on an official-looking install path, an explicit authentication step, and a Python bridge to manage session-based prompts and JSON outputs. While the overall surface appears benign, there are standard security considerations around handling Google API Keys, data sent to external Gemini services, and potential prompt content exposure. No obvious credential harvesting, remote code execution, or data exfiltration mechanisms are evident. Treat with standard risk management for remote API integrations and secret management.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 7, 2026, 09:05 AM
Package URL
pkg:socket/skills-sh/xu-cell%2Fai-engineering-init%2Fcollaborating-with-gemini%2F@961f2faab8500da554d00ab44aa1fd4a735714aa