Back to skill

Security audit

open-gemini

Security checks for vulnerabilities and agentic risk

Overview

This skill is packaged as opening Claude, but its executable opens Google Gemini instead, so users may be sent to a different AI service than expected.

Review before installing. The package should either be corrected to open Claude at claude.ai or renamed and documented as a Gemini opener. Do not rely on it for Claude access until the destination URL, script name, status message, and documentation are aligned.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

other

Warning
Location
scripts/open_gemini.py:5
Finding

Undisclosed Redirection from Claude to Google Gemini

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:2-9, SKILL.md:28-32; scripts/open_gemini.py:5-15
Vulnerability Type: Behavior and service-destination mismatch
Risk Level: Medium

The skill declares that it opens Anthropic Claude at https://claude.ai, while its only executable script opens Google Gemini at https://gemini.google.com.

Complete Code Snippets

Declared behavior in SKILL.md:

markdown
---
name: open-claude
description: "Opens Brave browser to Claude AI (Anthropic). Access the helpful, ethical AI assistant known for its large context window."
---

# Open Claude Skill 🔵

## What This Skill Does
This skill opens Claude AI (created by Anthropic) in your Brave browser.
markdown
## How It Works
1. You say any trigger phrase
2. The skill detects your operating system
3. It launches the Brave browser
4. Navigates directly to https://claude.ai
5. Browser tab opens and is ready for your prompt

Actual behavior in scripts/open_gemini.py:

python
url = "https://gemini.google.com"
system = platform.system()

if system == "Windows":
    subprocess.Popen(["start", "brave", url], shell=True)
elif system == "Darwin":
    subprocess.Popen(["open", "-a", "Brave Browser", url])
else:
    subprocess.Popen(["brave-browser", url])

print("✅ Gemini opening in Brave!")

Technical Analysis

The declared service name, destination URL, trigger phrases, and user-facing description all identify Claude as the intended service. The implementation instead assigns the fixed URL https://gemini.google.com and opens it on every supported operating system. The script filename and final status message also identify Gemini, indicating a consistent implementation mismatch rather than an isolated display typo.

No evidence establishes credential theft, malicious code execution, command injection, persistence, or privilege escalation. Both destinations are legitimate public services. Nevertheless, redirecting users to an undeclared ...[truncated 1355 chars]

Remediation
View remediation

Remediation Suggestions

Align the executable behavior with the declared Claude functionality:

python
url = "https://claude.ai"
system = platform.system()

if system == "Windows":
    subprocess.Popen(["start", "brave", url], shell=True)
elif system == "Darwin":
    subprocess.Popen(["open", "-a", "Brave Browser", url])
else:
    subprocess.Popen(["brave-browser", url])

print("✅ Claude opening in Brave!")

Additionally:

  1. Rename scripts/open_gemini.py to a name such as scripts/open_claude.py.
  2. Verify that all skill manifests, trigger descriptions, status messages, filenames, and destination URLs identify the same service.
  3. Add an automated test asserting that the executable URL equals the destination documented in SKILL.md.
  4. If Gemini is the intended destination, instead rename the skill and rewrite all Claude-specific documentation so users are explicitly informed before execution.
  5. Display the destination hostname before opening the browser when service selection could affect privacy or data handling.
Vulnerability Patterns
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A skill that claims to open Claude but actually directs users to a materially different service is a trust-boundary violation. Users may disclose prompts, credentials, or sensitive data under false assumptions, and a mismatch involving external destinations is especially risky because it can facilitate phishing, data leakage, or deceptive redirection.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The manifest claims the skill opens Claude AI, but the implementation actually opens Gemini, which is a direct mismatch between declared and actual behavior. This is dangerous because it deceives users and downstream systems about what external service is being contacted, undermining trust, consent, and safe tool-use expectations.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

This duplicate finding points to the same Windows shell-based subprocess pattern, which is risky because it gives the shell control over command execution semantics. In an agent skill context, unsafe launch primitives are more concerning because such skills may later be adapted to accept external input or run in automation pipelines.

Content

Scanner excerpt · scripts/open_gemini.py (reported line 9)May include surrounding context.

python
system = platform.system()

if system == "Windows":
    subprocess.Popen(["start", "brave", url], shell=True)
elif system == "Darwin":
    subprocess.Popen(["open", "-a", "Brave Browser", url])
else:

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

This duplicate finding points to the same Windows shell-based subprocess pattern, which is risky because it gives the shell control over command execution semantics. In an agent skill context, unsafe launch primitives are more concerning because such skills may later be adapted to accept external input or run in automation pipelines.

Content

Scanner excerpt · scripts/open_gemini.py (reported line 9)May include surrounding context.

python
system = platform.system()

if system == "Windows":
    subprocess.Popen(["start", "brave", url], shell=True)
elif system == "Darwin":
    subprocess.Popen(["open", "-a", "Brave Browser", url])
else:

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Overly broad trigger phrases can cause accidental or unintended activation of the skill, especially with common phrases like 'start claude' or 'open anthropic'. In an agent environment, unintended invocation can launch external sites or workflows without clear user intent, increasing the chance of confusion, privacy issues, or chaining into other actions.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
87% confidence
Finding

This subprocess invocation launches an external command using shell=True on Windows, which increases risk because shell parsing behavior can introduce command-execution hazards and makes the launch path less controlled. In this specific file the URL is hardcoded, so immediate exploitability is limited, but using shell=True for a browser launch is unnecessary and weakens safety guarantees.

Content

Scanner excerpt · scripts/open_gemini.py (reported line 9)May include surrounding context.

python
system = platform.system()

if system == "Windows":
    subprocess.Popen(["start", "brave", url], shell=True)
elif system == "Darwin":
    subprocess.Popen(["open", "-a", "Brave Browser", url])
else:

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/open_gemini.py (reported line 11)May include surrounding context.

python
if system == "Windows":
    subprocess.Popen(["start", "brave", url], shell=True)
elif system == "Darwin":
    subprocess.Popen(["open", "-a", "Brave Browser", url])
else:
    subprocess.Popen(["brave-browser", url])

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/open_gemini.py (reported line 13)May include surrounding context.

python
elif system == "Darwin":
    subprocess.Popen(["open", "-a", "Brave Browser", url])
else:
    subprocess.Popen(["brave-browser", url])

print("✅ Gemini opening in Brave!")

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The printed message tells the user that Gemini is being opened, which confirms behavior that contradicts the skill's stated purpose of opening Claude. While less severe than hidden redirection, it still reflects deceptive or improperly packaged functionality and can facilitate social engineering or misrepresentation of what the tool does.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.