Back to skill

Security audit

Gemini Deep Research

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Gemini Deep Research client that sends user research requests to Google's API and saves the returned report locally.

Install only if you are comfortable sending research prompts and any selected file-search context to Google's Gemini API. Do not use it with secrets, regulated data, or confidential business material unless that data is approved for this provider, and protect or delete the generated JSON metadata files when they may contain sensitive content.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Tainted flow: 'interaction_id' from os.environ.get (line 139, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/deep_research.py (reported line 63)May include surrounding context.

python
}
    
    while True:
        response = requests.get(
            f"{API_BASE}/interactions/{interaction_id}",
            headers=headers
        )

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill advertises capabilities that involve reading environment variables, making network requests, and writing files, but it does not declare an explicit tool or permission scope. That creates an authorization and review gap: operators and downstream systems cannot easily constrain or audit what the skill is allowed to access, increasing the chance of over-privileged execution or unintended data handling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill encourages optional file-search against user data and states that it saves full interaction metadata, but it does not warn that sensitive internal content may be sent to an external API or persisted locally in JSON output. In a research skill that performs systematic web search and synthesis, this context makes the issue more dangerous because users may supply proprietary reports, competitive intelligence, or personal data without understanding the exposure and retention risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script transmits the user query and optional file-search context to a remote Google API without an explicit privacy notice or confirmation step. Because this skill is specifically designed for deep research and multi-source synthesis, users may provide sensitive internal data, making undisclosed external transmission a meaningful privacy and data-governance risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/deep_research.py (reported line 42)May include surrounding context.

python
"file_search_store_names": [file_search_store]
        }]
    
    response = requests.post(
        f"{API_BASE}/interactions",
        headers=headers,
        json=payload

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script automatically writes the full research report and raw JSON response to local disk, which can persist sensitive prompts, proprietary research, file-search-derived content, or model outputs longer than the user expects. In a research skill, users may submit confidential business or technical material, so silent persistence increases data exposure risk on shared machines, repos, backups, or endpoint monitoring systems.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.