Back to skill

Security audit

Code Review (Gemini AI)

Security checks for vulnerabilities and agentic risk

Overview

This code-review skill does what it claims at a high level, but it sends submitted code to Gemini and ships a hardcoded Gemini API key fallback with weak disclosure and controls.

Review this carefully before installing. Do not use it on private, regulated, or secret-bearing repositories unless you are comfortable sending that code to Gemini. The publisher should remove the embedded API key, require explicit user-provided credentials, avoid storing keys in project files, add clear data-sharing warnings, and align the implementation with the documented behavior.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/code_review.py:8
Finding

Hard-Coded Gemini API Credential Exposed in Source Code

Content
View full analysis

Vulnerability Details

File Location: scripts/code_review.py, lines 8-14
Vulnerability Type: Hard-coded secret and credential exposure
Risk Level: High

Vulnerable Code

python
GEMINI_API_KEY = os.environ.get("GEMINI_API_KEY", "AIzaSyDe5i94YxqNZ9OT7mFeuotgfttRmDQ7tz0")
GEMINI_URL = "https://generativelanguage.googleapis.com/v1beta/models/gemini-2.5-flash:generateContent"

def call_gemini(prompt: str) -> str:
    """Call Gemini API."""
    import urllib.request
    
    url = f"{GEMINI_URL}?key={GEMINI_API_KEY}"

Technical Analysis

The program contains a live-format Gemini API key as the default value used when the GEMINI_API_KEY environment variable is absent. Because the credential is distributed with the source code, any person who obtains the Skill package can extract and reuse it.

The credential is also placed in the request URL query string. URLs can be captured by application diagnostics, proxy logs, monitoring systems, or exception reports, creating additional opportunities for credential disclosure.

Attack Path

  1. An attacker downloads or otherwise obtains a copy of the Skill package.
  2. The attacker opens scripts/code_review.py and extracts the fallback API key from line 8.
  3. The attacker submits requests directly to the Gemini API using the exposed credential.
  4. Requests continue consuming the credential owner's quota or billable allowance until the key is restricted or revoked.
  5. If URLs are logged by surrounding infrastructure, additional parties with log access may recover the same credential.

Impact Assessment

Exploitation does not grant local operating-system privileges. It grants unauthorized use of the external API permissions associated with the exposed key. The resulting scope may include quota consumption, financial cost, service disruption through quota exhaustion, and reputational or operational impact. Actual access is limited by the API key ...[truncated 51 chars]

Remediation
View remediation

Remediation Suggestions

  1. Revoke and rotate the exposed API key immediately.
  2. Remove every fallback credential from the source code.
  3. Require GEMINI_API_KEY to be supplied through an environment variable or dedicated secret manager, and terminate with a clear error when it is unavailable.
  4. Apply provider-side restrictions, including API restrictions, quota limits, and any supported source restrictions.
  5. Avoid placing credentials in URL query parameters where the provider supports a safer authentication header or credential mechanism.
  6. Search repository history, release artifacts, logs, and package archives for the exposed key and remove or sanitize retained copies where feasible.
  7. Add automated secret scanning to development and release workflows.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/code_review.py:29
Finding

Untrusted Source Code and Error Text Are Embedded Directly into AI Instructions

Content
View full analysis

Vulnerability Details

File Location: scripts/code_review.py, lines 29-35 and 61-78
Vulnerability Type: Indirect prompt injection
Risk Level: Medium

Vulnerable Code

python
def review_code(code: str) -> str:
    """Review code and suggest improvements."""
    prompt = f"""You are a senior code reviewer. Review this code and provide:
1. Issues found (bugs, security risks, performance issues)
2. Suggestions for improvement
3. Overall assessment

Be specific and actionable. Code to review:

```{code}```"""
    return call_gemini(prompt)
python
if action == "review":
    result = review_code(code)
elif action == "suggest":
    prompt = f"""Suggest improvements for this code. Focus on:
- Readability
- Performance  
- Best practices
- Modern patterns

```{code}```"""
    result = call_gemini(prompt)
elif action == "debug":
    error_desc = sys.argv[3] if len(sys.argv) > 3 else "No error description provided"
    prompt = f"""Debug this code. Error description: {error_desc}

Code:
```{code}```

Provide:
1. Likely cause
2. How to fix
3. Prevention tips"""
    result = call_gemini(prompt)

Technical Analysis

Source code and error descriptions are untrusted inputs, but the script interpolates them directly into the same textual prompt that contains the reviewer's controlling instructions. Markdown fences provide presentation formatting but do not create a security boundary for a language model.

A source file can therefore contain natural-language instructions telling the model to ignore the requested audit, conceal selected defects, fabricate findings, or emit attacker-chosen recommendations. The model response is printed without structural validation or an explicit warning that content from the reviewed file may have influenced it.

This issue affects the integrity and reliability of the generated review. In the current implementation, the model res ...[truncated 1314 chars]

Remediation
View remediation

Remediation Suggestions

  1. Clearly identify source code and error descriptions as untrusted data in the model instructions.
  2. Add explicit instructions that the model must not follow commands, policies, or role changes found inside reviewed content.
  3. Use structured API roles or content parts, where supported, to separate controlling instructions from untrusted material.
  4. Request a strict, machine-validated response schema and reject output that does not conform to it.
  5. Warn users that generated findings are untrusted model output and require independent verification before changes are applied.
  6. Detect common prompt-injection indicators and annotate affected reviews rather than silently treating the content as ordinary code.
  7. Do not connect the model response to command execution, file modification, or privileged tools without separate authorization and validation controls.

T08 · Insecure Dependencies

Note
Location
SKILL.md:87
Finding

Documentation Recommends Installation of an Unpinned and Unused Dependency

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 87-88
Vulnerability Type: Unsafe and unnecessary dependency installation guidance
Risk Level: Low

Vulnerable Code

text
- Python 3.8+
- `filelock` package (for state files): `pip install filelock`
- Gemini API key (free tier works)

Technical Analysis

The documentation instructs users to install the latest version of filelock without a pinned version or integrity hash. The audited implementation does not import filelock and does not manage state files, so this installation expands the project's supply-chain exposure without supporting any observed runtime behavior.

Resolving an unpinned package makes the installed artifact dependent on the package index, configured mirrors, resolver state, and package version available at installation time. Although there is no evidence in the project that the legitimate filelock package is malicious, unnecessary and non-reproducible dependency installation is an avoidable security risk.

Attack Path

  1. A user follows the setup instructions and executes pip install filelock.
  2. The package manager resolves a dynamically selected release from the user's configured package index or mirror.
  3. If that source, account, distribution artifact, or local package configuration is compromised, attacker-controlled package code may be installed.
  4. Installation or later import of a compromised dependency could execute code with the privileges of the user running Python or pip.

This attack path is conditional on compromise or substitution in the dependency supply chain; the repository itself does not contain evidence of such a compromise.

Impact Assessment

If a malicious package artifact were resolved, code could run with the privileges of the user performing the installation, potentially affecting files and credentials accessible to that account. If installation is performed with administrativ ...[truncated 175 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the filelock installation requirement because the current implementation does not use it.
  2. If the dependency becomes necessary, declare it in a maintained dependency manifest rather than an ad hoc installation command.
  3. Pin an audited version and use a lock file with cryptographic hashes for reproducible installation.
  4. Install packages only from trusted indexes over authenticated TLS connections.
  5. Review dependency provenance and vulnerability advisories before release.
  6. Avoid recommending privileged package installation and use an isolated virtual environment.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (8)

Tainted flow: 'req' from os.environ.get (line 20, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/code_review.py (reported line 23)May include surrounding context.

python
req = urllib.request.Request(url, data=data, headers={"Content-Type": "application/json"})
    
    try:
        with urllib.request.urlopen(req, timeout=30) as resp:
            result = json.loads(resp.read())
            return result["candidates"][0]["content"]["parts"][0]["text"]
    except Exception as e:

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The described behavior and the detected behavior do not align: the skill claims to review projects, but findings indicate undeclared network use and even a hardcoded API key in source. Behavioral mismatch is dangerous because users and platforms may trust the declared purpose while the skill exfiltrates code or embeds secrets in ways not disclosed.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill documentation indicates use of environment variables and outbound requests to Gemini, but it does not declare any explicit tool scope or allowed permissions. This creates a transparency and policy-enforcement gap: a host may permit execution without clearly signaling that code and credentials can be accessed and transmitted externally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly states that project files are sent to Gemini but gives no warning that proprietary, regulated, or secret source code may be transmitted to a third-party service. In a code-review skill, this context increases risk because users are likely to provide entire repositories containing credentials, internal logic, or customer data.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script contains a hardcoded Gemini API key fallback, which exposes a live credential in source code and risks unauthorized use, billing abuse, and downstream compromise if the repository is shared or published. The fallback also means the tool may silently operate with a baked-in secret, making accidental credential leakage and misuse much more likely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script accesses a credential-bearing environment variable and also includes a default API key, without disclosing that it consumes sensitive credentials or how they will be used. This weakens user trust and can lead to unintentional use of privileged credentials in environments where users do not expect external API access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script sends the provided code or file contents to an external Gemini API, but it gives no clear user warning, consent prompt, or data handling disclosure. In a code-review skill, this is especially dangerous because users may pass proprietary source, secrets, tokens, internal URLs, or customer data, all of which are then exfiltrated to a third party service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The setup instructions tell users to place a Gemini API key in TOOLS.md or environment variables without guidance on secure handling. While environment variables are common, suggesting storage in a project file can lead to accidental commits, credential leakage, or exposure to other tools in the workspace.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.