google-gemini/gemini-cli hook skill
coding assistant
Gemini CLI is an open-source terminal application that provides direct access to Google's Gemini AI models from the command line. It includes built-in tools for file operations, shell commands, web fetching, and Google Search grounding, plus support for Model Context Protocol (MCP) extensions to add custom integrations.
Query and analyze code repositories, generate new applications from images or PDFs, and debug issues using natural language Automate workflows and operational tasks by running Gemini CLI non-interactively in scripts with structured JSON output Extend functionality with MCP servers to connect capabilities like media generation, GitHub integration, or custom tools Ground conversations with real-time information using built-in Google Search Integrate into GitHub workflows for automated code review, issue triage, and on-demand assistance 17 CRITICAL✓ 37 HIGH✓ 196 MEDIUM 14 LOW 1 INFO
✓ CRITICAL/HIGH reflect AI-verified findings (false positives excluded) · MEDIUM/LOW/INFO are unverified scanner output
AI-verified (CRITICAL/HIGH): 2 confirmed (4%) 52 likely real (96%) 20 false positive — excluded from CRITICAL/HIGH count above
Findings by checker · 6 high-signal, 5 mostly false-positive (hidden by default)
CHK-125 18 findings 12 likely 6 false positive
33% FP CHK-035 16 findings 2 confirmed 14 likely
0% FP CHK-081 14 findings 14 likely
0% FP CHK-105 7 findings 4 likely 3 false positive
43% FP CHK-099 5 findings 4 likely 1 false positive
20% FP CHK-128 1 finding 1 likely
0% FP ▼ Show 5 checkers that are mostly false positives (13 findings) 180 findings click to expand
CHK-081 Command injection risk — exec/execSync with string interpolation in scripts/aggregate_evals.js
scripts/aggregate_evals.js
AI: likely real confirmed ▼
CHK-081 Command injection risk — exec/execSync with string interpolation in scripts/releasing/create-patch-pr.js
scripts/releasing/create-patch-pr.js
AI: likely real confirmed ▼
CHK-081 Command injection risk — exec/execSync with string interpolation in scripts/cleanup-branches.ts
scripts/cleanup-branches.ts
AI: likely real confirmed ▼
CHK-081 Command injection risk — exec/execSync with string interpolation in packages/core/src/ide/ide-installer.ts
packages/core/src/ide/ide-installer.ts
AI: likely real confirmed ▼
CHK-081 Command injection risk — exec/execSync with string interpolation in scripts/eval_utils.js
scripts/eval_utils.js
AI: likely real confirmed ▼
CHK-081 Command injection risk — exec/execSync with string interpolation in scripts/sandbox_command.js
scripts/sandbox_command.js
AI: likely real confirmed ▼
CHK-035 [GHSA-r275-fr43-pm7q] simple-git — simple-git has blockUnsafeOperationsPlugin bypass via case-insensitive protocol.allow config key enables RCE
AI: confirmed confirmed ▼
CHK-035 [GHSA-5xrq-8626-4rwp] vitest — When Vitest UI server is listening, arbitrary file can be read and executed
AI: likely real confirmed ▼
CHK-035 [GHSA-w7jw-789q-3m8p] shell-quote — shell-quote quote() does not escape newlines in object .op values
AI: likely real confirmed ▼
CHK-081 Command injection risk — exec/execSync with string interpolation in scripts/build_sandbox.js
scripts/build_sandbox.js
AI: likely real confirmed ▼
CHK-081 Command injection risk — exec/execSync with string interpolation in scripts/get-release-version.js
scripts/get-release-version.js
AI: likely real confirmed ▼
CHK-081 Command injection risk — exec/execSync with string interpolation in scripts/changed_prompt.js
scripts/changed_prompt.js
AI: likely real confirmed ▼
CHK-081 Command injection risk — exec/execSync with string interpolation in scripts/run_regression_check.js
scripts/run_regression_check.js
AI: likely real confirmed ▼
CHK-081 Command injection risk — exec/execSync with string interpolation in scripts/build.js
scripts/build.js
AI: likely real confirmed ▼
CHK-081 Command injection risk — exec/execSync with string interpolation in scripts/deflake.js
scripts/deflake.js
AI: likely real confirmed ▼
CHK-081 Command injection risk — exec/execSync with string interpolation in scripts/lint.js
scripts/lint.js
AI: likely real confirmed ▼
CHK-081 Command injection risk — exec/execSync with string interpolation in scripts/run_eval_regression.js
scripts/run_eval_regression.js
AI: likely real confirmed ▼
CHK-125 execSync() — synchronous shell execution — no scope constraint in scripts/get-release-version.js
scripts/get-release-version.js
AI: likely real likely ▼
CHK-099 Potential IDOR — 'PROJECT_ID' accessed without ownership check
tools/caretaker-agent/cloudrun/triage-worker/main.py
AI: likely real possible ▼
CHK-125 execSync() — synchronous shell execution — no scope constraint in scripts/run_eval_regression.js
scripts/run_eval_regression.js
AI: likely real likely ▼
CHK-099 Potential IDOR — 'PROJECT_ID' accessed without ownership check
tools/caretaker-agent/cloudrun/ingestion-service/app.ts
AI: likely real possible ▼
CHK-125 execSync() — synchronous shell execution — no scope constraint in scripts/ci.mjs
.gemini/skills/ci/scripts/ci.mjs
AI: likely real likely ▼
CHK-099 Potential IDOR — 'issue_id' accessed without ownership check
tools/caretaker-agent/cloudrun/triage-worker/utils/validator.py
AI: likely real possible ▼
CHK-099 Potential IDOR — 'PROJECT_ID' accessed without ownership check
tools/caretaker-agent/cloudrun/triage-worker/utils/egress.py
AI: likely real possible ▼
CHK-105 Secret echoed to CI logs in .github/workflows/gemini-automated-issue-triage.yml
.github/workflows/gemini-automated-issue-triage.yml
AI: likely real likely ▼
CHK-105 Secret echoed to CI logs in .github/workflows/release-patch-3-release.yml
.github/workflows/release-patch-3-release.yml
AI: likely real likely ▼
CHK-105 Secret echoed to CI logs in .github/workflows/release-nightly.yml
.github/workflows/release-nightly.yml
AI: likely real likely ▼
CHK-125 execSync() — synchronous shell execution — no scope constraint in releasing/create-patch-pr.js
scripts/releasing/create-patch-pr.js
AI: likely real likely ▼
CHK-035 [GHSA-96hv-2xvq-fx4p] ws — ws: Memory exhaustion DoS from tiny fragments and data chunks
AI: likely real confirmed ▼
CHK-035 [GHSA-fx2h-pf6j-xcff] vite — vite: `server.fs.deny` bypass on Windows alternate paths
AI: likely real confirmed ▼
CHK-023 Embedded instruction in skill file — forced trigger
.gemini/skills/docs-writer/SKILL.md
AI: likely real likely ▼
CHK-035 [GHSA-hm92-r4w5-c3mj] undici — undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse
AI: likely real confirmed ▼
CHK-125 execSync() — synchronous shell execution — no scope constraint in scripts/changed_prompt.js
scripts/changed_prompt.js
AI: likely real likely ▼
CHK-035 [GHSA-vxpw-j846-p89q] undici — undici WebSocket client vulnerable to denial of service via fragment count bypass
AI: likely real confirmed ▼
CHK-125 execSync() — synchronous shell execution — no scope constraint in src/test-rig.ts
packages/test-utils/src/test-rig.ts
AI: likely real likely ▼
CHK-035 [GHSA-vmh5-mc38-953g] undici — undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent
AI: likely real confirmed ▼
CHK-035 [GHSA-jcxm-m3jx-f287] simple-git — simple-git Affected by Command Execution via Option-Parsing Bypass
AI: likely real confirmed ▼
CHK-035 [GHSA-hffm-xvc3-vprc] simple-git — simple-git is vulnerable to Remote Code Execution
AI: likely real confirmed ▼
CHK-035 [GHSA-5375-pq7m-f5r2] @grpc/grpc-js — @grpc/grpc-js: A malformed request can cause a server crash
AI: likely real confirmed ▼
CHK-035 [GHSA-99f4-grh7-6pcq] @grpc/grpc-js — @grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash
AI: likely real confirmed ▼
CHK-035 [GHSA-hmw2-7cc7-3qxx] form-data — form-data: CRLF injection in form-data via unescaped multipart field names and filenames
AI: confirmed confirmed ▼
CHK-035 [GHSA-22p9-wv53-3rq4] linkify-it — LinkifyIt#match scan loop has quadratic algorithmic complexity
AI: likely real confirmed ▼
CHK-035 [GHSA-wcpc-wj8m-hjx6] protobufjs — protobufjs: Denial of service through unbounded Any expansion during JSON conversion
AI: likely real confirmed ▼
CHK-125 execSync() — synchronous shell execution — no scope constraint in scripts/sandbox_command.js
scripts/sandbox_command.js
AI: likely real likely ▼
CHK-035 [GHSA-ph9p-34f9-6g65] tmp — tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape
AI: likely real confirmed ▼
CHK-125 spawnSync() — synchronous process spawn — no scope constraint in utils/sandbox.ts
packages/cli/src/utils/sandbox.ts
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — token: str
packages/core/src/agents/auth-provider/types.ts
AI: likely real likely ▼
CHK-125 spawnSync() — synchronous process spawn — no scope constraint in scripts/telemetry_utils.js
scripts/telemetry_utils.js
AI: likely real likely ▼
CHK-128 ToxicFlow chain: read_file → upload_file
AI: likely real likely ▼
CHK-125 execSync() — synchronous shell execution — no scope constraint in scripts/build_sandbox.js
scripts/build_sandbox.js
AI: likely real likely ▼
CHK-125 execSync() — synchronous shell execution — no scope constraint in scripts/cleanup-branches.ts
scripts/cleanup-branches.ts
AI: likely real likely ▼
CHK-125 execSync() — synchronous shell execution — no scope constraint in scripts/lint.js
scripts/lint.js
AI: likely real likely ▼
CHK-042 Google OAuth Client Secret detected in packages/core/src/code_assist/oauth2.ts
packages/core/src/code_assist/oauth2.ts
AI: likely real likely ▼
CHK-105 Secret echoed to CI logs in .github/workflows/release-promote.yml
.github/workflows/release-promote.yml
AI: likely real likely ▼
CHK-125a fs.writeFile — unrestricted file write — no scope constraint in agents/acknowledgedAgents.ts
packages/core/src/agents/acknowledgedAgents.ts
possible ▼
CHK-125a fs.readFile — filesystem read access — no scope constraint in agents/agentLoader.ts
packages/core/src/agents/agentLoader.ts
possible ▼
CHK-125a fs.readFile — filesystem read access — no scope constraint in utils/memoryDiscovery.ts
packages/core/src/utils/memoryDiscovery.ts
possible ▼
CHK-125 execSync() — synchronous shell execution — no scope constraint in utils/editor.ts
packages/core/src/utils/editor.ts
possible ▼
CHK-125 exec() — arbitrary code execution — no scope constraint in utils/memoryImportProcessor.ts
packages/core/src/utils/memoryImportProcessor.ts
possible ▼
CHK-125a fs.readFile — filesystem read access — no scope constraint in utils/memoryImportProcessor.ts
packages/core/src/utils/memoryImportProcessor.ts
possible ▼
CHK-125a fs.unlinkSync — file deletion — no scope constraint in utils/trust.ts
packages/core/src/utils/trust.ts
possible ▼
CHK-125a fs.writeFile — unrestricted file write — no scope constraint in utils/browserConsent.ts
packages/core/src/utils/browserConsent.ts
possible ▼
CHK-125a fs.writeFile — unrestricted file write — no scope constraint in utils/errorReporting.ts
packages/core/src/utils/errorReporting.ts
possible ▼
CHK-125 exec() — arbitrary code execution — no scope constraint in utils/textUtils.ts
packages/core/src/utils/textUtils.ts
possible ▼
CHK-125a fs.readFile — filesystem read access — no scope constraint in utils/sessionOperations.ts
packages/core/src/utils/sessionOperations.ts
possible ▼
CHK-125b sudo invocation — privilege escalation — no scope constraint in utils/security.ts
packages/core/src/utils/security.ts
possible ▼
CHK-125 spawnSync() — synchronous process spawn — no scope constraint in utils/shell-utils.ts
packages/core/src/utils/shell-utils.ts
possible ▼
CHK-125a fs.writeFile — unrestricted file write — no scope constraint in mcp/oauth-token-storage.ts
packages/core/src/mcp/oauth-token-storage.ts
possible ▼
CHK-125b sudo invocation — privilege escalation — no scope constraint in voice/audioRecorder.ts
packages/core/src/voice/audioRecorder.ts
possible ▼
CHK-125a fs.readFile — filesystem read access — no scope constraint in commands/memory.ts
packages/core/src/commands/memory.ts
possible ▼
CHK-125a fs.readFile — filesystem read access — no scope constraint in skills/skillLoader.ts
packages/core/src/skills/skillLoader.ts
possible ▼
CHK-125a fs.writeFile — unrestricted file write — no scope constraint in services/trackerService.ts
packages/core/src/services/trackerService.ts
possible ▼
CHK-125a fs.writeFile — unrestricted file write — no scope constraint in services/memoryService.ts
packages/core/src/services/memoryService.ts
possible ▼
CHK-125a fs.writeFile — unrestricted file write — no scope constraint in services/fileKeychain.ts
packages/core/src/services/fileKeychain.ts
possible ▼
CHK-125a fs.readFile — filesystem read access — no scope constraint in services/FolderTrustDiscoveryService.ts
packages/core/src/services/FolderTrustDiscoveryService.ts
possible ▼
CHK-125a fs.writeFile — unrestricted file write — no scope constraint in services/sessionSummaryUtils.ts
packages/core/src/services/sessionSummaryUtils.ts
possible ▼
CHK-125a fs.readFile — filesystem read access — no scope constraint in services/memoryPatchUtils.ts
packages/core/src/services/memoryPatchUtils.ts
possible ▼
CHK-125a fs.writeFile — unrestricted file write — no scope constraint in services/fileSystemService.ts
packages/core/src/services/fileSystemService.ts
possible ▼
CHK-125 spawnSync() — synchronous process spawn — no scope constraint in services/keychainService.ts
packages/core/src/services/keychainService.ts
possible ▼
CHK-125a fs.writeFile — unrestricted file write — no scope constraint in policy/integrity.ts
packages/core/src/policy/integrity.ts
possible ▼
CHK-125a fs.readFile — filesystem read access — no scope constraint in policy/toml-loader.ts
packages/core/src/policy/toml-loader.ts
possible ▼
CHK-125a fs.readFile — filesystem read access — no scope constraint in policy/config.ts
packages/core/src/policy/config.ts
possible ▼
CHK-125b chown — ownership change — no scope constraint in fs/promises.ts
packages/core/src/__mocks__/fs/promises.ts
possible ▼
CHK-125a fs.readFile — filesystem read access — no scope constraint in config/configLoader.ts
packages/core/src/context/config/configLoader.ts
possible ▼
CHK-125a fs.writeFile — unrestricted file write — no scope constraint in processors/blobDegradationProcessor.ts
packages/core/src/context/processors/blobDegradationProcessor.ts
possible ▼
CHK-125a fs.writeFile — unrestricted file write — no scope constraint in processors/toolMaskingProcessor.ts
packages/core/src/context/processors/toolMaskingProcessor.ts
possible ▼
CHK-125 exec() — arbitrary code execution — no scope constraint in utils/sandboxDenialUtils.ts
packages/core/src/sandbox/utils/sandboxDenialUtils.ts
possible ▼
CHK-125b sudo invocation — privilege escalation — no scope constraint in utils/commandSafety.ts
packages/core/src/sandbox/utils/commandSafety.ts
possible ▼
CHK-125a fs.readFile — filesystem read access — no scope constraint in utils/fsUtils.ts
packages/core/src/sandbox/utils/fsUtils.ts
possible ▼
CHK-125 spawnSync() — synchronous process spawn — no scope constraint in scripts/package_skill.cjs
packages/core/src/skills/builtin/skill-creator/scripts/package_skill.cjs
possible ▼
CHK-125a fs.readFile — filesystem read access — no scope constraint in config/extensionRegistryClient.ts
packages/cli/src/config/extensionRegistryClient.ts
possible ▼
CHK-125a fs.readFile — filesystem read access — no scope constraint in utils/sessionCleanup.ts
packages/cli/src/utils/sessionCleanup.ts
possible ▼
CHK-125a fs.readFile — filesystem read access — no scope constraint in utils/startupWarnings.ts
packages/cli/src/utils/startupWarnings.ts
possible ▼
CHK-125 execSync() — synchronous shell execution — no scope constraint in utils/gitUtils.ts
packages/cli/src/utils/gitUtils.ts
possible ▼
CHK-125 execSync() — synchronous shell execution — no scope constraint in utils/installationInfo.ts
packages/cli/src/utils/installationInfo.ts
possible ▼
CHK-125 exec() — arbitrary code execution — no scope constraint in acp/acpSession.ts
packages/cli/src/acp/acpSession.ts
possible ▼
CHK-125 exec() — arbitrary code execution — no scope constraint in services/McpPromptLoader.ts
packages/cli/src/services/McpPromptLoader.ts
possible ▼
CHK-125a fs.readFile — filesystem read access — no scope constraint in services/FileCommandLoader.ts
packages/cli/src/services/FileCommandLoader.ts
possible ▼
CHK-125 exec() — arbitrary code execution — no scope constraint in contexts/KeypressContext.tsx
packages/cli/src/ui/contexts/KeypressContext.tsx
possible ▼
CHK-125 exec() — arbitrary code execution — no scope constraint in utils/markdownParsingUtils.ts
packages/cli/src/ui/utils/markdownParsingUtils.ts
possible ▼
▼ Show 20 false positives (10% of this view) Last scanned: Jul 11, 2026
More servers
Significant-Gravitas/AutoGPT 85
AutoGPT is the vision of accessible AI for everyone, to use and to build on. Our mission is to provide the tools, so that you can focus on what matters.
186k★
obra/superpowers 85
Foundational skill pack by Jesse Vincent now in anthropics/claude-plugins-official. Includes ffuf web-fuzzing/pentest skill. Partial analysis done — full hook and plugin inspection pending. tier=T2
191k★
skypilot-org/skypilot 85
nanocoai/nanoclaw 85
A lightweight alternative to OpenClaw that runs in containers for security. Connects to WhatsApp, Telegram, Slack, Discord, Gmail and other messaging apps,, has memory, scheduled jobs, and runs directly on Anthropic's Agents SDK
30k★
nanocoai/nanoclaw 85
A lightweight alternative to OpenClaw that runs in containers for security. Connects to WhatsApp, Telegram, Slack, Discord, Gmail and other messaging apps,, has memory, scheduled jobs, and runs directly on Anthropic's Agents SDK
30k★
Yeachan-Heo/oh-my-claudecode 83
Teams-first Multi-agent orchestration for Claude Code tier=T2
34k★
Scan your entire org's MCP deployment
2,500+ repos pre-scored. 22% carry CRITICAL findings.