Back to skill

Security audit

Gemini Image Simple

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Gemini image generator/editor that uses a user-provided API key and sends prompts or input images to Google as part of its stated purpose.

Install this only if you are comfortable sending image prompts and any --input image to Google's Gemini API using your GEMINI_API_KEY. Avoid using confidential images or secrets in prompts unless that external processing is acceptable for your use case.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/generate.py (reported line 22)May include surrounding context.

python
def get_api_key():
    """Get API key from environment."""
    key = os.environ.get("GEMINI_API_KEY")
    if not key:
        print("Error: GEMINI_API_KEY environment variable not set", file=sys.stderr)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill uses sensitive capabilities—environment access for GEMINI_API_KEY and outbound network access to Google's API—but does not declare an explicit tool scope such as permissions or allowed-tools. This creates a transparency and policy-enforcement gap: users and platforms cannot easily reason about or restrict what the skill is allowed to access, increasing the risk of unintended secret exposure or unauthorized external communication.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill description and usage guidance do not clearly warn that user prompts and any input images are sent to Google's Gemini API for processing. This is dangerous because users may provide confidential text or sensitive images under the false assumption that processing is local, especially given the emphasis on 'stdlib only' and 'works anywhere' rather than remote data handling.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.