gemini-cli — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited gemini-cli (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Interact w/ Google's Gemini CLI locally. Run queries, get responses, compare outputs.
Gemini CLI must be installed & configured:
gemini & sign in w/ Google accountgemini --versionIMPORTANT: Use -p flag for non-interactive (headless) one-shot queries. Without -p, gemini opens interactive mode which hangs in automation.
# One-shot query (MUST use -p for non-interactive)
gemini -p "Your prompt"
# Specific model
gemini -p "prompt" -m gemini-3-pro
# JSON output
gemini -p "prompt" -o json
# Auto-approve tool use (-y is deprecated)
gemini --approval-mode=yolo -p "prompt"
# File analysis
cat file.txt | gemini -p "Analyze this"| Alias | Use case |
|---|---|
auto | DEFAULT — routes per prompt (simple → Flash, complex → 3 Pro) |
pro | Force Gemini 3 Pro (best all-round) |
flash / flash-lite | Fast, lightweight tasks (3.5 Flash GA rolling out as auto default) |
Omit -m to use auto routing. Aliases beat pinned model ids — they track upstream model swaps. Pin a full id (e.g. gemini-3-pro) only when the user names one.
| Flag | Desc |
|---|---|
-p | Required for headless. Non-interactive prompt |
-m | Model selection |
-o | Output: text/json/stream-json |
--approval-mode=yolo | Auto-approve all actions (-y is deprecated) |
-d | Debug mode |
-s | Sandbox mode |
-r | Resume session |
-i | Execute prompt then continue interactive |
gemini -p "prompt"-p for automation/one-shot queries-o json for parsing~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.