Gemini
This page lists the packages that declare Gemini as their target: Gemini Extensions and the MCP servers Gemini connects to. We track Gemini Extensions as their own package kind, separate from MCP servers. If the list is short today, that's the current state of the registry, not a broken filter: non-MCP package kinds were added recently and fill in as source expansion lands.
We run the same scanner suite on every one: agent-config safety, known-vulnerable dependencies, data-flow SAST, and detectors we wrote ourselves: nerlo-behavioral for obfuscated decode-then-exec code and nerlo-install-instruction for install docs that direct you to run a bundled or fetched file.
We show every scanner's verdict separately at one flat rank. The composite score is a subordinate summary; it never hides a finding.
We track 803 packages that target Gemini, out of 47,540 registry-wide.
No findings does not mean no risk. Nerlo aggregates automated scanner output; automated scanning is one layer of defence, not a substitute for review.
Explore Gemini Packages
Filter by security badge, search packages by keyword or publisher, and inspect side-by-side scanner scorecards for all Gemini packages in the primary registry.
Browse all Gemini packages in Registry →