gemini-cli - 💡(How to fix) Fix Security scan results for gemini-cli — MCPSafe AIVSS 45/100 (Grade F)

Official PRs (…)
ON THIS PAGE

Recommended Tools

×6

Utilities matched from this issue’s tags and category — try them while you read without losing context.

GitHub issue graph ai analysis

Paste a GitHub issue URL. We fetch that issue, discover linked issues from bodies/comments/timeline, collect linked pull requests, and produce a structured English report.

The report is written in English Markdown for sharing and archival.

Helpful · Quick feedback

Loading…

Code Example

[![MCPSafe](https://api.mcpsafe.io/badge/github/google-gemini/gemini-cli.svg)](https://mcpsafe.io/registry/github/google-gemini/gemini-cli)
RAW_BUFFERClick to expand / collapse

Hi team 👋

I ran a free deep security scan of google-gemini/gemini-cli using MCPSafe — a purpose-built scanner for MCP servers using a 5-LLM consensus panel to detect prompt injection risks, over-scoped tool schemas, supply chain issues, and more.

Results: 45/100 · Grade F

SeverityCount
🔴 Critical0
🟠 High3
🟡 Medium71
🟢 Low10

Summary: 3 high + 71 medium + 10 low findings — significant exposure in a widely-used Google Gemini CLI tool

📋 Full report with findings and evidence: https://mcpsafe.io/registry/github/google-gemini/gemini-cli


Add a security badge to your README

[![MCPSafe](https://api.mcpsafe.io/badge/github/google-gemini/gemini-cli.svg)](https://mcpsafe.io/registry/github/google-gemini/gemini-cli)

This badge auto-updates whenever a new scan runs — great for showing users and enterprise customers your security posture at a glance.


Feel free to close this if you're already tracking these findings. Happy to answer any questions about specific findings.

— Truong BUI · mcpsafe.io

Vote matrix · Quick signals

Works
Did the solution work? Tap to confirm.
Easy Fix
Was it a quick fix?
Time Saver
Did it save you time?
Blocking
Was it severely blocking?
Common Issue
Are others likely hitting this too?
Flaky / Intermittent
Is it intermittent?
Verified / Reproducible
Can you reproduce it reliably?
Loading…

Still need to ship something?

×6

Another batch ranked right after the header list — different links, same matching logic.

Back to top recommendations

TRENDING