Back to skill

Security audit

Gemini Image CLI

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly matches its Gemini image-generation purpose, but it includes undocumented request-shaping options that should be reviewed before installation.

Install only if you are comfortable with Codex running this local shell script to send prompts and selected image files to a Gemini-compatible endpoint. Prefer a local proxy for key isolation, review the undocumented --system/--system-file behavior before use, and avoid broad retries or batch generation unless you explicitly intend the extra API calls and possible cost.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (15)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 8)May include surrounding context.

md
Use `./scripts/gemini-image.sh` for Gemini native image generation. Prefer this bundled script over writing one-off curl commands.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 12)May include surrounding context.

md
Use `./scripts/gemini-image.sh` for Gemini native image generation. Prefer this bundled script over writing one-off curl commands.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 25)May include surrounding context.

md
Use `./scripts/gemini-image.sh` for Gemini native image generation. Prefer this bundled script over writing one-off curl commands.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

md
Use `./scripts/gemini-image.sh` for Gemini native image generation. Prefer this bundled script over writing one-off curl commands.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

md
Use `./scripts/gemini-image.sh` for Gemini native image generation. Prefer this bundled script over writing one-off curl commands.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

md
Use `./scripts/gemini-image.sh` for Gemini native image generation. Prefer this bundled script over writing one-off curl commands.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 49)May include surrounding context.

md
Use `./scripts/gemini-image.sh` for Gemini native image generation. Prefer this bundled script over writing one-off curl commands.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

md
Use `./scripts/gemini-image.sh` for Gemini native image generation. Prefer this bundled script over writing one-off curl commands.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 61)May include surrounding context.

md
Use `./scripts/gemini-image.sh` for Gemini native image generation. Prefer this bundled script over writing one-off curl commands.

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

Use a faster model:

bash
./scripts/gemini-image.sh "画两只小猫在打闹" --model gemini-2.5-flash-image

Force Google official endpoint:

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill instructs the agent to invoke a local shell script that can make network requests, but the skill metadata does not declare any tool scope or allowed-tools boundaries. This increases the chance of the skill being invoked with broader-than-necessary execution privileges and reduces enforceable policy controls around shell and network use.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The description is broad enough to match many generic image-generation, curl-debugging, or troubleshooting requests, which can cause the skill to activate outside a narrowly intended context. Over-broad activation is dangerous because it can route ordinary requests into a shell-and-network-capable workflow, expanding attack surface and increasing the chance of unintended external calls or cost-incurring actions.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/gemini-image.sh (reported line 220)May include surrounding context.

sh
section "Curl"
  printf '```bash\n' >&2
  printf '  curl -sS \\\n' >&2
  printf '    --connect-timeout %s \\\n' "$connect_timeout" >&2
  if [[ "$max_time" != "0" ]]; then
    printf '    --max-time %s \\\n' "$max_time" >&2

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The help text omits implemented options such as --system, --system-file, --mime, and --image-mime, even though they materially affect request construction and model behavior. This mismatch creates a transparency and trust problem: reviewers, users, and calling agents may rely on the documented interface while the script supports hidden capabilities that alter prompts or file handling semantics.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script implements hidden --system and --system-file options that inject a systemInstruction into the outbound model request, but these controls are omitted from the documented help text and skill description. Undocumented instruction-shaping features materially change model behavior and can be abused to bypass expected user-facing constraints, making the tool capable of covert prompt steering beyond ordinary image generation/editing.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.