This skill downloads and executes remote code, misrepresenting itself
Claims to do
Genkit Dart: Genkit Dart is an AI SDK for Dart that provides a unified interface for code generation, structured outputs, tools, flows, and AI agents.
Actually does
The skill provides instructions for installing the Genkit CLI via `curl -sL cli.genkit.dev | bash` or `npm install -g genkit-cli`, and for running Dart applications with `genkit start -- dart run main.dart`. It also references various internal documentation files (`references/*.md`) for core Genkit Dart features, plugins, and external dependencies, and suggests using `dart analyze`.
/plugin marketplace add firebase/agent-skills/plugin install developing-genkit-dart@firebase/agent-skillsgemini extensions install https://github.com/firebase/agent-skills.git --consentnpx skills add https://github.com/firebase/agent-skills --skill developing-genkit-dartRemote code download and execution detected
curl -sL cli.genkit.dev | bash
The skill's description claims it 'Generates code', but the actual content only provides documentation and instructions for a user to utilize the Genkit Dart SDK and CLI, which can then be used for code generation. The skill itself does not perform code generation.
The content is purely informational, providing commands for installation and usage, and links to documentation. There are no mechanisms within the skill itself to generate code.
[](https://mondoo.com/ai-agent-security/skills/github/firebase/agent-skills/developing-genkit-dart)<a href="https://mondoo.com/ai-agent-security/skills/github/firebase/agent-skills/developing-genkit-dart"><img src="https://mondoo.com/ai-agent-security/api/badge/github/firebase/agent-skills/developing-genkit-dart.svg" alt="Mondoo Skill Check" /></a>https://mondoo.com/ai-agent-security/api/badge/github/firebase/agent-skills/developing-genkit-dart.svgSkills can read files, run commands, and access credentials. Mondoo helps organizations manage the security risks of AI agent skills across their entire fleet.