cc-agy — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited cc-agy (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
python scripts/agy_bridge.py --cd "/path/to/project" --PROMPT "Your task"Output: JSON with success, SESSION_ID, agent_messages, and optional error / stderr.
usage: agy_bridge.py [-h] --PROMPT PROMPT --cd CD
[--model MODEL] [--SESSION_ID SESSION_ID]
[--sandbox] [--no-skip-permissions]
[--print-timeout PRINT_TIMEOUT]
[--return-all-messages]
{check,plugin} ...
Antigravity (agy) Bridge
options:
-h, --help show this help message and exit
--PROMPT PROMPT Instruction for the task to send to agy.
--cd CD Workspace root for agy (sets cwd + --add-dir).
--model MODEL Model alias (flash-low/medium/high, pro-low/high, sonnet,
opus, gpt-oss) or canonical string. Omit to use the
settings.json default.
--SESSION_ID SESSION_ID
Resume a conversation by UUID. Maps to agy --conversation.
--sandbox Run in agy sandbox mode.
--no-skip-permissions
Do NOT pass --dangerously-skip-permissions. WARNING:
with default toolPermission=request-review, print mode
WILL HANG. Only for interactive review workflows.
--print-timeout PRINT_TIMEOUT
agy --print-timeout (e.g. 5m, 10m). Default 10m.
--return-all-messages
Include reasoning + all type=15 steps in the response.
subcommands:
check Probe agy install / version / auth / current model.
plugin Thin passthrough to `agy plugin list|import|install|enable|disable`.Always capture `SESSION_ID` from the first response for follow-up (maps to agy --conversation <UUID>, which appends to the same conversation DB):
# Initial task
python scripts/agy_bridge.py --cd "/project" --PROMPT "Analyze auth in login.py"
# Continue with SESSION_ID
python scripts/agy_bridge.py --cd "/project" --SESSION_ID "uuid-from-response" --PROMPT "Write unit tests for that"Prototyping (request diffs):
python scripts/agy_bridge.py --cd "/project" --PROMPT "Generate unified diff to add logging" --model proSwitch model per call:
python scripts/agy_bridge.py --cd "/project" --PROMPT "Review this Rust" --model sonnet
python scripts/agy_bridge.py --cd "/project" --PROMPT "Same code" --model opusSetup check:
python scripts/agy_bridge.py checkManage skills/plugins (passthrough to agy):
python scripts/agy_bridge.py plugin list
python scripts/agy_bridge.py plugin import /path/to/pluginagy --print writes nothing to stdout. The bridge instead runs agy, discovers the new conversation SQLite DB at ~/.gemini/antigravity-cli/conversations/<UUID>.db, and extracts the assistant reply from the last step_type=15 row's step_payload protobuf (field f20 → f1). MCP servers (~/.gemini/antigravity/mcp_config.json), the memory doc (~/.gemini/GEMINI.md), and skills are pre-configured by the user and auto-loaded by agy — the bridge does not manage them.
By default the bridge passes --dangerously-skip-permissions to agy. This is mandatory for non-interactive `--print` mode because agy's default toolPermission is request-review, which blocks waiting for a human to approve tool calls — and since --print captures no TTY, the process hangs until timeout. With --dangerously-skip-permissions, agy auto-approves all tool calls. Only pass --no-skip-permissions if agy can service interactive permission prompts. The bridge always runs under a hard outer timeout (--print-timeout + 60s) so a hung agy cannot block indefinitely.
.proto file, reading the reply from field f1 inside field f20 of the last step_type=15 row. If agy changes its internal schema, extraction returns empty. Fix location: extract_answer() in scripts/agy_bridge.py.agy models returns empty on this build; model aliases are hardcoded.--continue is intentionally NOT exposed (target selection is opaque); use --SESSION_ID to resume a specific conversation.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.