Gemini Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Gemini Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Remote MCP server that exposes Google Gemini's text, image, video (Veo), and audio transcription capabilities as tools any MCP client (Claude.ai, Claude Code, Cowork) can call directly. Same architecture as the Bosta and Salestrail MCP connectors: Node.js + Express, deployed as a Render web service, talking to Gemini's REST API.
| Tool | What it does |
|---|---|
generate_text | Text generation — captions, copy, summaries, translation, analysis. Optional system_instruction. |
generate_image | Generate an image from a prompt, or edit/compose an existing one via reference_image_base64 (Nano Banana / Gemini image model). |
start_video_generation | Kicks off a Veo video job from a prompt (+ optional reference image for image-to-video). Returns an operation_name — generation takes ~1-6 min. |
check_video_status | Polls an operation_name from start_video_generation. Returns {"status":"pending"} or the finished video as an embedded base64 resource. |
transcribe_audio | Transcribes audio (m4a/mp3/wav/aac/ogg/flac) from base64, with an optional instruction (e.g. "transcribe in Egyptian Arabic"). |
All tools return MCP error results (isError: true) on failure rather than crashing the server — confirmed against the live Gemini API during build (an invalid key correctly came back as a tool error, not a connection drop).
~20MB total. Longer call recordings will need the Gemini File API (upload first, then reference by URI) — not implemented yet. Worth adding if your typical .m4a files are long.
audio/mp4 for .m4a files, since that'sthe container format (AAC inside MP4). This has not been verified against a real audio file yet. If Gemini rejects it, try audio/aac instead — pass it explicitly via the mime_type argument.
check_video_status tries a couple of known responseshapes (generateVideoResponse.generatedSamples[0].video and predictions[0]). Worth confirming against a real job once you have Veo access, since Google has changed this shape across API versions before.
check the Gemini API console if start_video_generation errors out.
npm install
cp .env.example .env # fill in GEMINI_API_KEY
npm startHealth check: curl http://localhost:3000/health
npm installnpm startGEMINI_API_KEY (and optionally the model overridesfrom .env.example) in Render's Environment tab.
https://<your-app>.onrender.com/mcp.Add it as a custom connector pointing at https://<your-app>.onrender.com/mcp, the same way Bosta MCP / Salestrail MCP are connected.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.