Is cluka-399/gemini-image-simple safe?
Yes. cluka-399/gemini-image-simple is safe to install. Oathe's behavioral security audit gave the gemini-image-simple skill by cluka-399 a trust score of 94/100 with 4 findings, none critical or high.
https://github.com/openclaw/skills/tree/main/skills/cluka-399/gemini-image-simple
Is cluka-399/gemini-image-simple safe to install?
This skill provides legitimate image generation functionality using Google's Gemini API with clean, straightforward Python code that uses only standard library modules. While monitoring detected some sensitive file access during the audit period, this appears to be related to SSH authentication rather than the skill itself.
What security issues were found in cluka-399/gemini-image-simple?
Category Scores
Findings (4)
INFO Environment Variable Access -10 ▶
Script accesses GEMINI_API_KEY environment variable as expected for API authentication
LOW Sensitive File Access During Audit -5 ▶
Monitoring detected access to credential files (.env, SSH keys, AWS credentials, etc.) during audit period, but appears to be from SSH authentication rather than the skill itself
INFO Python Script Execution -10 ▶
Contains executable Python script for image generation functionality using only standard library modules
INFO API Integration -5 ▶
Makes HTTP requests to Google's Gemini API for legitimate image generation functionality
Should I install cluka-399/gemini-image-simple?
Oathe's verdict for cluka-399/gemini-image-simple is SAFE with a trust score of 94/100. Recommendation: Install.