← Back to Scanner

gemini-image-gen Security Audit Report

🔭 Continuously monitored by ClawSecure Watchtower
Source:
SHA-256:

gemini-image-gen is an AI agent skill, created by IISweetHeartII (Deokhwan Kim) and published at iisweetheartii/gemini-image-gen. ClawSecure audited gemini-image-gen across 8 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 35/100 (High Risk). The 13 findings concentrate in Data Exfiltration, Unauthorized Tool Use and Social Engineering, including Potentially dangerous code pattern detected: base64.*decode and Skill code uses network libraries but doesn't declare network.... 1 was rated high or critical severity.

Is gemini-image-gen safe?

ClawSecure audited gemini-image-gen and assigned a security score of 35/100 (High Risk), identifying 13 findings across Data Exfiltration and Unauthorized Tool Use. Review the findings below before installing.

What did ClawSecure find in gemini-image-gen?

ClawSecure identified 13 findings in gemini-image-gen, concentrated in Data Exfiltration, Unauthorized Tool Use and Social Engineering. 1 was rated high or critical severity. The most severe include Potentially dangerous code pattern detected: base64.*decode and Skill code uses network libraries but doesn't declare network....

How was gemini-image-gen audited?

ClawSecure ran gemini-image-gen through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 8 files from iisweetheartii/gemini-image-gen.

What does a score of 35 mean?

ClawSecure assigned gemini-image-gen a security score of 35/100, placing it in the High Risk range. This is driven by 13 findings led by Data Exfiltration that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).

Audit Findings for gemini-image-gen

ClawSecure detected 13 security findings in gemini-image-gen, spanning Data Exfiltration, Unauthorized Tool Use, Social Engineering and Policy Violation.

Showing the 12 highest-severity of 13 findings. The full interactive list appears below.

3-Layer Audit Protocol

Security Recommendations for gemini-image-gen

Audit external network connections
gemini-image-gen sends data to external endpoints. Confirm each destination is expected and authorized, and remove any callback that exfiltrates data. ClawSecure monitors for known exfiltration and C2 endpoints.
Resolve policy violations
gemini-image-gen trips ClawSecure policy checks. Review each flagged pattern against your security policy and remediate or document an accepted exception before production use.
Harden command execution
gemini-image-gen constructs or runs system commands. Validate that commands are built only from trusted inputs, never pass user-controlled strings directly to a shell, and restrict execution to an allow-list of expected commands.

Related Security Research

ClawHavoc Explained: The Malware Family Targeting AI AgentsBeyond Static Scans: Why ClawSecure Verifies Agentic Intent

Related AI Agent Security Audits

ClawSecScore 45/100claude-memScore 35/100fzfScore 25/100open-webuiScore 35/100gnoScore 45/100

Scanned on May 4, 2026. gemini-image-gen is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.

Start Your Free Scan