Post cover image

May 15, 2026

When .. Costs You Everything: A Path Traversal in Gemini CLI's Skill Installer

TL;DR — A single missing character in a sanitizer regex allowed a malicious SKILL.md to recursively delete ~/.gemini and replace it with…

Farhad Sajid Barbhuiya

6 min read