Github Google Gemini Gemini Cli
Repository: gemini-cli
Author: google-gemini · Source status: Clear source
An open-source AI agent that brings the power of Gemini directly into your terminal.
Score basis:Clear source · Risk needs review · Universal
Repository: agentsmithy
Author: GoogleCloudPlatform · Source status: Clear source
AgentSmithy provides a series of tools and templates that simplify the process of building and deploying custom AI agents on Google Cloud.
Score basis:Clear source · Risk needs review · Universal
Trust level
83 · High trust
Strong recovered source and maintenance signals.
Risk decision
Review required
metadata-only
Install readiness
script-backed · copy-only command
SkillTrust only shows install guidance and copy actions; it never executes installs.
Before you install
Review source, permissions, and execution risk first, then alternatives. Scores prioritize review; they do not replace manual judgment.
Review weakest dimensions and next actions before copying commands.
Evidence or risk signals are incomplete; compare alternatives first.
Audit grade
C · Review first
Execution risk
High
Evidence confidence
65%
SAS-v2.1 radar
SAS-v2.1
Audit grade
C · Review first
Execution risk
High
Top threats
unexpected code execution, data exfiltration
Control gaps
missing license, broad permissions
Evidence confidence
65%
Repository
GoogleCloudPlatform/agentsmithy
Author
GoogleCloudPlatform
Community signal
83 stars · 21 forks
Last updated
2026-04-11
Primary source
GoogleCloudPlatform/agentsmithy
Source status
Clear source
Install method
script-backed
Command & code execution
34Focus: Whether it runs commands or scripts
Next action: Manually confirm command-running skills in an isolated directory.
High-risk action confirmation
38Focus: Whether destructive or external actions require confirmation
Next action: Avoid directly installing high-risk skills without confirmation controls.
Network & data egress
43Focus: Whether it may send data out
Next action: If unsure, restrict network access or allow only known domains.
Supported tools can change install steps; Universal entries need source review.
Explicitly supported
git clone https://github.com/GoogleCloudPlatform/agentsmithy.gitmetadata-only
Review source and permissions before copying install commands.
Evidence or risk signals are incomplete; compare alternatives first.
Focus: Who published it and whether it is traceable
Next action: Review repository, author, and README first; do not install directly when source is pending.
Focus: Whether install steps can be reviewed
Next action: Prefer candidates with install docs and repository evidence.
Focus: Whether tool descriptions may hide instructions
Next action: Read README, rules, and tool descriptions before install.
Focus: What it can access
Next action: Grant only task-required permissions and prefer Ask/manual confirmation.
Focus: Whether it runs commands or scripts
Next action: Manually confirm command-running skills in an isolated directory.
Focus: Whether file reads/writes can escape scope
Next action: Check working directory and file access scope before running.
Focus: Whether it may send data out
Next action: If unsure, restrict network access or allow only known domains.
Focus: Whether it handles tokens, private keys, or agent identity
Next action: Do not provide long-lived tokens or private keys to source-pending skills.
Focus: Whether external content can steer behavior
Next action: For browser/RAG/rules skills, review permissions and confirmation controls first.
Focus: Whether memory or retrieved context can be poisoned
Next action: Try RAG/memory skills in a low-privilege environment first.
Focus: Whether external tools and MCP access are clearly bounded
Next action: Confirm which external tools it will connect to before install, and start with the smallest possible set.
Focus: Whether destructive or external actions require confirmation
Next action: Avoid directly installing high-risk skills without confirmation controls.
Focus: How far impact can spread when something goes wrong
Next action: If unsure, test in an isolated project first.
Focus: Whether actions can be traced
Next action: Prefer candidates with logs or previews.
Focus: Whether it is maintained and reusable
Next action: Check license and maintenance before organizational use.
Strong recovered source and maintenance signals.
Phase 1 only shows installation-aware, source-backed signals. SkillTrust does not execute install scripts for users.
Risk factors
metadata-only
Permission hints
repository clone
Why related: Same task category, Keyword overlap...
Why related: Same task category, Keyword overlap, Similar install method
Repository: lobehub
Author: lobehub · Source status: Clear source
The ultimate space for work and life — to find, build, and collaborate with agent teammates that grow with you.
Score basis:Clear source · Risk needs review · Universal
Why related: Same task category, Keyword overlap...
Why related: Same task category, Keyword overlap, Similar install method
Repository: ansible
Author: ansible · Source status: Clear source
Ansible is a radically simple IT automation platform that makes your applications and systems easier to deploy and maintain.
Score basis:Clear source · Risk needs review · Universal
Why related: Same task category, Keyword overlap...
Why related: Same task category, Keyword overlap, Similar install method
Repository: PaddleOCR
Author: PaddlePaddle · Source status: Clear source
Turn any PDF or image document into structured data for your AI.
Score basis:Clear source · Risk needs review · Universal
Why related: Same task category, Keyword overlap...
Why related: Same task category, Keyword overlap, Similar install method
Repository: cline
Author: cline · Source status: Clear source
Autonomous coding agent right in your IDE, capable of creating/editing files, executing commands, using the browser, and more with your permission every step of the way.
Score basis:Clear source · Risk needs review · Universal
Why related: Same task category, Keyword overlap...
Why related: Same task category, Keyword overlap, Similar install method
Repository: huginn
Author: huginn · Source status: Clear source
Create agents that monitor and act on your behalf.
Score basis:Clear source · Risk needs review · Universal
Why related: Same task category, Keyword overlap...
Why related: Same task category, Keyword overlap, Similar install method
Repository: kubectl-ai
Author: GoogleCloudPlatform · Source status: Clear source
AI powered Kubernetes Assistant
Score basis:Clear source · Risk needs review · Universal
Repository: agent-starter-pack
Author: GoogleCloudPlatform · Source status: Clear source
Ship AI Agents to Google Cloud in minutes, not months.
Score basis:Clear source · Risk needs review · Universal
Repository: vertex-ai-samples
Author: GoogleCloudPlatform · Source status: Clear source
Notebooks, code samples, sample apps, and other resources that demonstrate how to use, develop and manage machine learning and generative AI workflows using Google Cloud Vertex AI.
Score basis:Clear source · Risk needs review · Universal
Repository: Open_Data_QnA
Author: GoogleCloudPlatform · Source status: Clear source
The Open Data QnA python library enables you to chat with your databases by leveraging LLM Agents on Google Cloud.
Score basis:Clear source · Risk needs review · Universal