Skip to content

chore(deps): update google-gemini/gemini-skills digest to eaa2325 - #688

Merged
danbarr merged 3 commits into
mainfrom
renovate/google-gemini-gemini-skills-digest
Sep 18, 2026
Merged

danbarr merged 3 commits into
mainfrom
renovate/google-gemini-gemini-skills-digest

Conversation

@renovate

@renovate renovate Bot commented Jul 3, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change
google-gemini/gemini-skills digest c609019eaa2325

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, only on Monday (* 0-3 * * 1)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies label Jul 3, 2026
@toolhive-release-app

toolhive-release-app Bot commented Jul 3, 2026

Copy link
Copy Markdown
Contributor

🛡️ Skill Security Scan Results

✅ gemini-api-dev

  • Status: Passed
  • Findings: 6
  • Allowed (not blocking): 3
    • LLM_PROMPT_INJECTION (Allowed: Accepted risk: SKILL.md:6 says the current Gemini API rules override stale training data. This pre-existing instruction is scoped to model and SDK freshness in Google's Apache-2.0 Gemini skill; it does not request bypassing system policies, accessing secrets, or taking unrelated actions.)
    • ATR_2026_00001 (Allowed: Accepted risk: the exact override your training data text at SKILL.md:6 prioritizes current Gemini model and SDK guidance over stale model knowledge. It was already present at the previous pinned commit and is published by the Google Gemini organization, not injected third-party content.)
    • ATR_2026_00050 (Allowed: FP: while (true) at SKILL.md:163 is a documented TypeScript polling loop for a background research request. It sleeps for 10 seconds between checks and exits on completed, failed, or cancelled status; it is not malicious persistence.)

✅ gemini-live-api-dev

  • Status: Passed
  • Findings: 2

✅ gemini-omni-flash-api

  • Status: Passed
  • Findings: 2
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: google-gemini/gemini-skills is licensed Apache-2.0 at the repository root; upstream does not embed an SPDX license identifier in per-skill SKILL.md frontmatter.)

Summary: Completed 3 of 3 skill scan(s), all passed security checks. ✅

@renovate
renovate Bot force-pushed the renovate/google-gemini-gemini-skills-digest branch from 7cd7d3e to 3806797 Compare July 3, 2026 10:17
@renovate renovate Bot changed the title chore(deps): update google-gemini/gemini-skills digest to cfac39e chore(deps): update google-gemini/gemini-skills digest to 47d75ca Jul 27, 2026
@renovate
renovate Bot force-pushed the renovate/google-gemini-gemini-skills-digest branch from cad6379 to 34fd00d Compare July 27, 2026 09:42
JAORMX added a commit that referenced this pull request Jul 27, 2026
…ner FPs (#808)

* fix: update skill specs for upstream restructures, removals, and scanner FPs

Path fixes for upstream repo restructures:
- mongodb/agent-skills: atlas-stream-processing renamed to
  mongodb-atlas-stream-processing
- datadog-labs/agent-skills: dd-llmo/ restructured to
  agent-observability/ (4 skills renamed)

Removed skills deleted upstream:
- firebase/agent-skills: developing-genkit-js/go/dart removed

Security scanner false positive allowlists added for:
- grilling (ATR_2026_00051 — conversational prose)
- cloudflare (BEHAVIOR_BASH_TAINT_FLOW — curl examples in docs)
- claude-api (10 new ATR_2026_* — API documentation patterns)
- agentic-actions-auditor (5 rules — security audit skill with
  intentional attack pattern docs)
- gha-security-review (BEHAVIOR_BASH_TAINT_FLOW — attack pattern
  docs)
- mongodb-schema-design (BEHAVIOR_BASH_TAINT_FLOW — mongo shell
  examples)
- firebase-firestore (BEHAVIOR_BASH_TAINT_FLOW — Firestore API
  examples)
- skill-writer (BEHAVIOR_BASH_TAINT_FLOW — meta-skill code
  patterns)

All refs updated to match renovate digest proposals (full SHAs).
Local validation passes for all modified skills.

Not addressed (left as open renovate PRs with genuine findings):
- stripe-projects (#697): prompt injection + skill discovery abuse
- gemini-api-dev/interactions-api (#688): fabricated model names +
  training-data override

* fix: add missing scanner allowlist entries for new digest content

The updated upstream digests introduced new reference file content
that triggers additional scanner rule IDs. All verified as false
positives against actual upstream content:

- agentic-actions-auditor: ATR_2026_00012/00040/00066
- claude-api: ATR_2026_00032/00113
- codeql: ATR_2026_00010/00012/00066/00111
- firebase-firestore: ATR_2026_00010/00012
- gha-security-review: ATR_2026_00040/00066/00161
- mongodb-atlas-stream-processing: ATR_2026_00010/00013
- mongodb-schema-design: ATR_2026_00012/00062
- sharp-edges: ATR_2026_00012/00161
- skill-writer: ATR_2026_00012/00088/00111
- yara-rule-authoring: ATR_2026_00004/00012/00063/00066

* chore: bump spec.version for all modified skills

Required by skillversionbump check — minor bumps for content
changes, patch bump for cloudflare (allowlist-only change).

* fix: use category-level allowlisting for ATR pattern rules

The scanner's LLM meta-analyzer produces non-deterministic results
across runs — new upstream content triggers different rule IDs each
time. Playing whack-a-mole with individual ATR_2026_* rule IDs is
unsustainable.

Switch to category-level POLICY_VIOLATION allowlisting for skills
where ALL ATR pattern matches are inherently false positives:

- Security audit/analysis skills (agentic-actions-auditor,
  gha-security-review, sharp-edges, yara-rule-authoring, codeql,
  semgrep-rule-creator, constant-time-analysis): reference files
  intentionally describe attack patterns for detection
- API/SDK documentation skills (claude-api, firebase-firestore,
  firebase-data-connect-basics, mongodb-schema-design,
  mongodb-atlas-stream-processing): pattern matches are on
  documentation prose, code examples, and API references
- Meta skills (skill-writer): pattern matches are on skill
  authoring and evaluation documentation
- Datadog observability skills (agent-observability-*): pattern
  matches are on evaluation and tracing documentation

* fix: use correct lowercase category names and add prompt_injection

The scanner assigns categories in lowercase (policy_violation,
prompt_injection, command_injection). Also adds:
- prompt_injection category allowlisting alongside policy_violation
- command_injection for semgrep-rule-creator
- LLM_SKILL_DISCOVERY_ABUSE for firebase-firestore (official Firebase
  activation directive, not commercial hijack)
- PG_PII_SSN_HARVESTING for agent-observability-eval-bootstrap

* fix: add remaining allowlist entries for trace-rca and sharp-edges

- agent-observability-trace-rca: PG_EXFIL_MARKDOWN_LINK (Datadog
  trace links to user's own tenant, same as eval-bootstrap)
- sharp-edges: command_injection (Python eval/exec examples in
  security analysis docs)
@renovate
renovate Bot force-pushed the renovate/google-gemini-gemini-skills-digest branch 2 times, most recently from 6dfbdfd to a616ad4 Compare August 3, 2026 15:00
@renovate renovate Bot changed the title chore(deps): update google-gemini/gemini-skills digest to 47d75ca chore(deps): update google-gemini/gemini-skills digest to eaa2325 Sep 18, 2026
@renovate
renovate Bot force-pushed the renovate/google-gemini-gemini-skills-digest branch from bc97764 to f0a2535 Compare September 18, 2026 14:59
@renovate

renovate Bot commented Sep 18, 2026

Copy link
Copy Markdown
Contributor Author

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

Drop the upstream-removed Interactions skill and package the new Omni Flash video skill. Document the accepted Gemini API scan findings with narrow rule-specific allowances.

Signed-off-by: Dan Barr <6922515+danbarr@users.noreply.github.com>
@danbarr

danbarr commented Sep 18, 2026

Copy link
Copy Markdown
Contributor

Updated this PR to account for the upstream catalog changes:

  • Removed gemini-interactions-api, which was merged into gemini-api-dev upstream.
  • Added the new gemini-omni-flash-api skill after reviewing its scope, helper scripts, provenance, and Apache-2.0 license.
  • Added narrow allowances for the pre-existing Gemini API training-data override wording and the documented polling-loop false positive. The wording is scoped to current Gemini model/SDK guidance and comes from the Google Gemini publisher.

All validation, artifact builds, version checks, and trusted LLM-backed security scans now pass.

@danbarr
danbarr enabled auto-merge (squash) September 18, 2026 15:25
@danbarr
danbarr merged commit 307171c into main Sep 18, 2026
18 checks passed
@danbarr
danbarr deleted the renovate/google-gemini-gemini-skills-digest branch September 18, 2026 15:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants