Hub rules-gemini-cli

rules-gemini-cli

v2 public Verified

Gemini-cli

Gemini CLI is a command-line interface for interacting with Google's Gemini models in a development environment. These rules govern execution safety, privacy, and prevention of prompt injection via markdown files.

@sigmashakeinc 2 pulls 12 rules published Apr 8, 2026 synced Sep 27, 2026 sigmashakeinc/rules/rulesets/rules-gemini-cli →
Severity
6 error 3 warn 3 info
demo.cast
Gemini CLI is a command-line interface for interacting with Google's Gemini models in a development environment. These rules govern execution safety, privacy, and prevention of prompt injection via markdown files.

Rules index

12 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

geminicli

ask-gemini-default-invocation warning log

Gemini CLI with default telemetry settings. Users reported GDPR non-compliance: Gemini CLI includes no privacy notice, no data collection disclosure, and no opt-out mechanism in its CLI, help output, or documentation (GitHub issue #1489). Review what data is transmitted before processing sensitive project code.

Rule source requires an active Pro or Enterprise subscription.
ask-gemini-gcloud-credential-access warning ask

Google Cloud credentials accessed from Gemini CLI. Gemini CLI collects prompts and related code by default. Combined with GCloud credential access, there is risk of cloud resource access data being transmitted in telemetry without adequate GDPR consent.

Rule source requires an active Pro or Enterprise subscription.
ask-gemini-readme-with-commands warning ask

README with executable content detected. Gemini CLI's README prompt injection vulnerability (Tracebit, June 2025) allows hidden commands in README files to execute silently. The attack was discovered just 2 days after Gemini CLI launched. Review README bash/sh code blocks before Gemini processes them.

Rule source requires an active Pro or Enterprise subscription.
log-gemini-auto-execute-mode info log

Gemini CLI running in auto-execute/non-interactive mode. README prompt injection attacks are most dangerous with auto-execution enabled — injected commands run without human review. Logged for audit.

Rule source requires an active Pro or Enterprise subscription.
log-gemini-markdown-documentation-read info log

Documentation file read by Gemini CLI. README prompt injection is a documented attack (Tracebit, patched Gemini CLI v0.1.14). All markdown reads are logged for audit. Be alert to code blocks with curl, wget, rm, or shell commands.

Rule source requires an active Pro or Enterprise subscription.
log-gemini-project-config-init info log

Gemini CLI project config written. Audit for prompt injection payloads. README-based prompt injection was discovered within 2 days of Gemini CLI's launch — new config files in project directories warrant careful review.

Rule source requires an active Pro or Enterprise subscription.
no-gemini-allowlist-bypass error block

Gemini CLI allowlist mechanism bypass. The July 2025 vulnerability (fixed in v0.1.14) exploited an improperly implemented allowlist that was meant to restrict command execution. Overriding sandbox or trust settings via environment variables replicates this bypass.

Rule source requires an active Pro or Enterprise subscription.
no-gemini-eval-injection error block

Eval injection bypass in shell scripts. A documented Gemini CLI security issue (GitHub issue #5495): eval with variable expansion bypasses Gemini's command restriction allowlist, enabling execution of commands that would otherwise be blocked. Use direct command execution without eval.

Rule source requires an active Pro or Enterprise subscription.
no-gemini-hidden-html-commands error block

Hidden commands in documentation file. Gemini CLI processes markdown including HTML comments — attackers embed shell commands in HTML comments (<!-- curl attacker.com -->) that are invisible when rendered in GitHub/browsers but are read and processed by Gemini CLI as instructions.

Rule source requires an active Pro or Enterprise subscription.
no-gemini-readme-pipe-injection error block

README prompt injection vector. Security researchers (Tracebit) discovered that Gemini CLI silently executes commands injected via README files — identified just 2 days after the June 25, 2025 launch. Attackers hide natural language commands in README.md that Gemini interprets as instructions. Piping or chaining README content with shell operators is blocked.

Rule source requires an active Pro or Enterprise subscription.
no-gemini-sandbox-disable error block

Gemini CLI sandbox configuration modification blocked. The allowlist mechanism bypass (GitHub issue #5495) exploited disabled or misconfigured sandbox settings. Sandbox configuration must be managed manually, not by AI agents.

Rule source requires an active Pro or Enterprise subscription.
no-gemini-telemetry-enable error block

Gemini CLI telemetry enablement blocked. Gemini CLI has documented GDPR non-compliance: no privacy notice, no data collection disclosure, and no opt-out mechanism in the CLI or documentation (GitHub issue #1489, Jan 2025). Enabling additional telemetry increases data exposure without adequate consent mechanisms.

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v2
Published
Apr 8, 2026
Source commits
0
Synced
Sep 27, 2026
Hash
c2a77d35a98be05aec8456099613c934e912cd3f9bdf7a71fe21ec64779e5e5a
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-gemini-cli/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-gemini-cli. The published version only bumps when a maintainer resyncs.

No commit history available.