Antigravity CLI

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only helper for Google Antigravity CLI, with risky CLI options disclosed and cautioned rather than hidden.

Install this only if you intend to use Antigravity CLI. Keep sandboxing and permission prompts enabled by default, avoid `--dangerously-skip-permissions` and `always-proceed` except in trusted low-risk workspaces, and be cautious with remote installer commands.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The documentation exposes a clearly dangerous flag, `--dangerously-skip-permissions`, and describes it as auto-approving all tool requests without any nearby warning, constraints, or safe-use guidance. In a CLI skill meant to help users run and configure an agentic tool, normalizing this option can lead users to disable an important security control and allow unreviewed tool execution.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal