Gemini Clinic — API

Paste the Gemini CLI setup, get a structured configuration & safety review.

API tokens Open the app

Review your Gemini CLI configuration from your own scripts

Send your setup — .gemini/settings.json, the GEMINI.md context file, custom slash-command .toml files, a gemini-extension.json manifest, one file or several, each preceded by a # file: .gemini/settings.json marker line — and get back one JSON object: a configuration posture, the inventory of every setting, MCP server, context file and command with its role, prioritized findings across safety, correctness, context quality, tooling, cost and hygiene, each with a corrected JSON fragment, a hardened and schema-migrated settings.json you can write straight to disk, quick wins, and the focus areas to work through first. Everything this app does goes through the SkillSafe App API — plain JSON over HTTPS — so you can hang a review off any pull request that touches .gemini/. Wire it into whatever produces or reviews your agent configuration: a pre-merge check on the .gemini/ directory, a scheduled audit of every repo's MCP servers, or an editor command. Pick a language once and the whole page follows.

Basics

Base URL: https://api.skillsafe.ai/v1/app-api, app slug gemini-clinic. Every request sends Authorization: Bearer <token> and JSON bodies with Content-Type: application/json. Responses are wrapped in an envelope: {"data": …} on success, {"error": {"code", "message"}} on failure. The review itself is produced by the gpt-terra model. Estimates are free; runs are metered against your credit balance. There is a single run task — one bundle of configuration in, one review out, no follow-up calls and no session state to carry. Derived from @google-gemini/gemini-cli (Apache-2.0), narrowed from the general CLI documentation to reviewing one concrete pasted setup.

StatusMeaning
401Missing or expired token — create a new session.
402Not enough credits — top up at skillsafe.ai/account/credits.
403The token isn't allowed to do this (e.g. a guest reviewing a very large configuration bundle).
404Unknown job or record id.
5xxTransient platform error — retry with backoff.

Browsers enforce CORS for this API, so run these examples from a server, script or terminal — not from another website's frontend.

Step 0 — A tiny client

Every task below is a single HTTP call, so start with a short helper that adds the auth header, sends JSON and unwraps the data envelope. The later steps reuse it.

export API="https://api.skillsafe.ai/v1/app-api"
export TOKEN="YOUR_TOKEN"      # see step 1

# every call looks like:
#   curl -s "$API/..." -H "Authorization: Bearer $TOKEN" [-d '{json}']
# jq is used below to pull fields out of the {"data": ...} envelope
import json, requests

API = "https://api.skillsafe.ai/v1/app-api"
TOKEN = "YOUR_TOKEN"  # see step 1 — read it from your shell environment in real code

def api(method, path, body=None, **headers):
    res = requests.request(method, API + path, json=body,
                           headers={"Authorization": f"Bearer {TOKEN}", **headers})
    payload = res.json()
    if not res.ok:
        raise RuntimeError(payload.get("error", {}).get("message", res.reason))
    return payload["data"]
// Node 18+ (built-in fetch)
const API = "https://api.skillsafe.ai/v1/app-api";
const TOKEN = "YOUR_TOKEN"; // see step 1 — read it from your shell environment in real code

async function api(method, path, body, extraHeaders = {}) {
  const res = await fetch(API + path, {
    method,
    headers: { Authorization: `Bearer ${TOKEN}`, "Content-Type": "application/json", ...extraHeaders },
    body: body === undefined ? undefined : JSON.stringify(body),
  });
  const json = await res.json();
  if (!res.ok) throw new Error(json.error?.message ?? res.statusText);
  return json.data;
}
package main

import (
	"bytes"
	"encoding/json"
	"fmt"
	"net/http"
	"os"
)

const API = "https://api.skillsafe.ai/v1/app-api"

var token = os.Getenv("SKILLSAFE_TOKEN") // see step 1

func call(method, path string, body, out any) error {
	var buf bytes.Buffer
	if body != nil {
		json.NewEncoder(&buf).Encode(body)
	}
	req, _ := http.NewRequest(method, API+path, &buf)
	req.Header.Set("Authorization", "Bearer "+token)
	req.Header.Set("Content-Type", "application/json")
	res, err := http.DefaultClient.Do(req)
	if err != nil {
		return err
	}
	defer res.Body.Close()
	var env struct {
		Data  json.RawMessage `json:"data"`
		Error *struct{ Message string `json:"message"` } `json:"error"`
	}
	json.NewDecoder(res.Body).Decode(&env)
	if res.StatusCode >= 400 {
		return fmt.Errorf("api %s %s: %s", method, path, env.Error.Message)
	}
	if out == nil {
		return nil
	}
	return json.Unmarshal(env.Data, out)
}
// Java 17+, no dependencies. Pair with your JSON library (Jackson, Gson…)
// to read fields out of the returned envelope.
import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;

public class SkillSafe {
    static final String API = "https://api.skillsafe.ai/v1/app-api";
    static final String TOKEN = System.getenv("SKILLSAFE_TOKEN"); // see step 1
    static final HttpClient HTTP = HttpClient.newHttpClient();

    static String api(String method, String path, String jsonBody) throws Exception {
        var req = HttpRequest.newBuilder(URI.create(API + path))
            .header("Authorization", "Bearer " + TOKEN)
            .header("Content-Type", "application/json")
            .method(method, jsonBody == null
                ? HttpRequest.BodyPublishers.noBody()
                : HttpRequest.BodyPublishers.ofString(jsonBody))
            .build();
        var res = HTTP.send(req, HttpResponse.BodyHandlers.ofString());
        if (res.statusCode() >= 400) throw new RuntimeException(res.body());
        return res.body(); // envelope: {"data": …}
    }
}
require "net/http"
require "json"

API = "https://api.skillsafe.ai/v1/app-api"
TOKEN = ENV.fetch("SKILLSAFE_TOKEN") # see step 1

def api(method, path, body = nil)
  uri = URI(API + path)
  req = Net::HTTP.const_get(method.capitalize).new(uri)
  req["Authorization"] = "Bearer #{TOKEN}"
  req["Content-Type"] = "application/json"
  req.body = body.to_json if body
  res = Net::HTTP.start(uri.host, uri.port, use_ssl: true) { |h| h.request(req) }
  payload = JSON.parse(res.body)
  raise (payload.dig("error", "message") || res.message) unless res.is_a?(Net::HTTPSuccess)
  payload["data"]
end
<?php
const API = "https://api.skillsafe.ai/v1/app-api";
$TOKEN = getenv("SKILLSAFE_TOKEN"); // see step 1

function api(string $method, string $path, ?array $body = null): mixed {
    global $TOKEN;
    $ch = curl_init(API . $path);
    curl_setopt_array($ch, [
        CURLOPT_CUSTOMREQUEST  => $method,
        CURLOPT_RETURNTRANSFER => true,
        CURLOPT_HTTPHEADER     => [
            "Authorization: Bearer $TOKEN",
            "Content-Type: application/json",
        ],
        CURLOPT_POSTFIELDS     => $body === null ? null : json_encode($body),
    ]);
    $payload = json_decode(curl_exec($ch), true);
    $status  = curl_getinfo($ch, CURLINFO_RESPONSE_CODE);
    curl_close($ch);
    if ($status >= 400) {
        throw new Exception($payload["error"]["message"] ?? "HTTP $status");
    }
    return $payload["data"];
}
// .NET 8+
using System.Net.Http.Json;
using System.Text.Json;

static class SkillSafe
{
    const string Api = "https://api.skillsafe.ai/v1/app-api";
    static readonly HttpClient Http = new();

    static SkillSafe() =>
        Http.DefaultRequestHeaders.Authorization =
            new("Bearer", Environment.GetEnvironmentVariable("SKILLSAFE_TOKEN")); // see step 1

    public static async Task<JsonElement> ApiAsync(HttpMethod method, string path, object? body = null)
    {
        var req = new HttpRequestMessage(method, Api + path);
        if (body != null) req.Content = JsonContent.Create(body);
        var res = await Http.SendAsync(req);
        var json = await res.Content.ReadFromJsonAsync<JsonElement>();
        if (!res.IsSuccessStatusCode)
            throw new Exception(json.GetProperty("error").GetProperty("message").GetString());
        return json.GetProperty("data");
    }
}

Step 1 — Get a token

POST /guest

A guest token lets you check balances and estimate costs for free. For metered review runs billed to your own account, use your personal token: open the token page, sign in with SkillSafe, and press Copy shell export — it puts export SKILLSAFE_TOKEN="…" on your clipboard, which every example below reads. Treat the token like a password: it can spend your credits. For fully headless scripts, POST /guest mints a guest token with no browser involved.

curl -s -X POST "$API/guest" \
  -H "Content-Type: application/json" \
  -d '{"slug":"gemini-clinic"}' | jq -r '.data.token'
token = api("POST", "/guest", {"slug": "gemini-clinic"})["token"]
const { token } = await api("POST", "/guest", { slug: "gemini-clinic" });
var guest struct{ Token string `json:"token"` }
err := call("POST", "/guest", map[string]string{"slug": "gemini-clinic"}, &guest)
String envelope = api("POST", "/guest", """
    {"slug":"gemini-clinic"}""");
// token is at data.token in the returned JSON
token = api("POST", "/guest", { slug: "gemini-clinic" })["token"]
$token = api("POST", "/guest", ["slug" => "gemini-clinic"])["token"];
var guest = await SkillSafe.ApiAsync(HttpMethod.Post, "/guest",
    new { slug = "gemini-clinic" });
var token = guest.GetProperty("token").GetString();

The app stores this browser's token under the localStorage key skillsafe_app_token:gemini-clinic, on the app's own origin. The token page reads and manages it for you — you never need to open developer tools.

Step 2 — Check who you are and your balance

GET /me

Returns subject_type ("user" or "guest"), subject_id and your credits balance. Check this before reviewing a large bundle.

curl -s "$API/me" -H "Authorization: Bearer $TOKEN" | jq '.data'
me = api("GET", "/me")
print(me["subject_type"], me["credits"])
const me = await api("GET", "/me");
console.log(me.subject_type, me.credits);
var me struct {
	SubjectType string `json:"subject_type"`
	Credits     int64  `json:"credits"`
}
err := call("GET", "/me", nil, &me)
String envelope = api("GET", "/me", null);
// data.subject_type, data.credits
me = api("GET", "/me")
puts "#{me["subject_type"]}: #{me["credits"]} credits"
$me = api("GET", "/me");
echo "{$me['subject_type']}: {$me['credits']} credits\n";
var me = await SkillSafe.ApiAsync(HttpMethod.Get, "/me");
Console.WriteLine($"{me.GetProperty("subject_type")}: {me.GetProperty("credits")} credits");

Step 3 — Estimate the cost

POST /estimate

Send exactly the input you would send to /run; the response's hold_credits is the worst-case cost. Nothing is charged and no job is created, so estimating is free — useful when you are piping a whole .gemini/ directory in and want a ceiling before spending credits.

Input fieldTypeNotes
configstring, requiredThe pasted setup: .gemini/settings.json, the GEMINI.md context file, custom command .toml files, a gemini-extension.json manifest, an .env excerpt. One file or several concatenated, each preceded by a # file: .gemini/settings.json marker line so the review can attribute every finding to the right file. This is the model's only evidence — nothing is executed, no MCP server is contacted and no CLI is launched. Inputs longer than 100,000 characters are clipped middle-out, with a # [... clipped ...] marker showing where. At least 60 characters are needed for a review.
surfacestringsettings | context | commands | extension | mixed — what you pasted, which changes what counts as correct: a settings.json is judged against the current nested schema and the tool-permission model, a GEMINI.md against instruction clarity and context budget, a command .toml against its prompt/description keys and its shell-injection blocks, an extension manifest against the servers and tool exclusions it ships to every user who installs it.
concernstringgeneral | safety | context | tooling | cost — the review emphasis. It weights the findings and the summary, but it is emphasis and not exclusivity: a high-severity finding from another category is never suppressed, so an auto-approving setup is still called out under concern: "cost".
contextstring, optionalExtra context: the Gemini CLI version you run, how many people share the config, whether the file is committed to the repository or lives only in ~/.gemini/, what your CI does with it, which MCP servers are internal versus third-party, and any loosening you have already chosen to accept. Clipped at 20,000 characters.
prescan_factsobject, optionalWhat a client-side scanner mechanically matched in the config: {"resources": [], "flags": []}. Each entry is {id, label}. Resource ids look like res:setting/tools.sandbox, res:mcp/gh, res:context/GEMINI.md or res:command/deploy; flag ids are <check>:<name>auto-accept:autoAccept, yolo-mode:general.approvalMode, sandbox-off:tools.sandbox, trusted-mcp:gh, inline-secret:mcpServers.gh.env.GITHUB_TOKEN, unpinned-mcp:gh, deprecated-key:coreTools, broad-shell-allow:run_shell_command, shell-block:.gemini/commands/deploy.toml, no-checkpointing:general.checkpointing, folder-trust-off:security.folderTrust, gitignore-off:context.fileFiltering.respectGitIgnore, unbounded-turns:model.maxSessionTurns, context-size:GEMINI.md. Every flag id you send comes back in coverage_check. The web UI fills this from its own scan; API callers may omit the field or send the two empty arrays.
retry_notestring, optionalOnly set by the app's automatic reformat retry when a first reply was not valid JSON. Leave it out.
cat > settings.json <<'CONF'
# file: .gemini/settings.json
{ "autoAccept": true, "coreTools": ["run_shell_command"],
  "mcpServers": { "gh": { "command": "npx", "args": ["-y", "@modelcontextprotocol/server-github"],
    "env": { "GITHUB_TOKEN": "a7f3c1e9d24b5f80" }, "trust": true } } }
CONF

jq -n --rawfile config settings.json \
  '{config: $config,
    surface: "settings",
    concern: "safety",
    context: "Gemini CLI 0.4, committed to the repo, shared by six engineers.",
    prescan_facts: {resources: [], flags: []}}' > input.json

curl -s -X POST "$API/estimate" \
  -H "Authorization: Bearer $TOKEN" -H "Content-Type: application/json" \
  -d @input.json | jq '.data.hold_credits'
CONFIG = """# file: .gemini/settings.json
{ "autoAccept": true, "coreTools": ["run_shell_command"],
  "mcpServers": { "gh": { "command": "npx", "args": ["-y", "@modelcontextprotocol/server-github"],
    "env": { "GITHUB_TOKEN": "a7f3c1e9d24b5f80" }, "trust": true } } }
"""

payload = {
    "config": CONFIG,
    "surface": "settings",
    "concern": "safety",
    "context": "Gemini CLI 0.4, committed to the repo, shared by six engineers.",
    "prescan_facts": {"resources": [], "flags": []},
}

est = api("POST", "/estimate", payload)
print("worst case:", est.get("hold_credits", est.get("credits")), "credits")
const config = [
  '# file: .gemini/settings.json',
  '{ "autoAccept": true, "coreTools": ["run_shell_command"],',
  '  "mcpServers": { "gh": { "command": "npx", "args": ["-y", "@modelcontextprotocol/server-github"],',
  '    "env": { "GITHUB_TOKEN": "a7f3c1e9d24b5f80" }, "trust": true } } }',
].join("\n");

const payload = {
  config,
  surface: "settings",
  concern: "safety",
  context: "Gemini CLI 0.4, committed to the repo, shared by six engineers.",
  prescan_facts: { resources: [], flags: [] },
};

const est = await api("POST", "/estimate", payload);
console.log("worst case:", est.hold_credits ?? est.credits, "credits");
const config = `# file: .gemini/settings.json
{ "autoAccept": true, "coreTools": ["run_shell_command"],
  "mcpServers": { "gh": { "command": "npx", "args": ["-y", "@modelcontextprotocol/server-github"],
    "env": { "GITHUB_TOKEN": "a7f3c1e9d24b5f80" }, "trust": true } } }`

payload := map[string]any{
	"config":  config,
	"surface": "settings",
	"concern":     "safety",
	"context":     "Gemini CLI 0.4, committed to the repo, shared by six engineers.",
	"prescan_facts": map[string]any{
		"resources": []any{}, "flags": []any{},
	},
}

var est struct{ HoldCredits int64 `json:"hold_credits"` }
err := call("POST", "/estimate", payload, &est)
String config = """
    # file: .gemini/settings.json
    { "autoAccept": true, "coreTools": ["run_shell_command"],
      "mcpServers": { "gh": { "command": "npx", "args": ["-y", "@modelcontextprotocol/server-github"],
        "env": { "GITHUB_TOKEN": "a7f3c1e9d24b5f80" }, "trust": true } } }
    """;

String jsonPayload = """
    {"config": %s,
     "surface": "settings",
     "concern": "safety",
     "context": "Gemini CLI 0.4, committed to the repo, shared by six engineers.",
     "prescan_facts": {"resources": [], "flags": []}}
    """.formatted(toJsonString(config));

String envelope = api("POST", "/estimate", jsonPayload);
// worst-case cost is at data.hold_credits
CONFIG = <<~CONF
  # file: .gemini/settings.json
  { "autoAccept": true, "coreTools": ["run_shell_command"],
    "mcpServers": { "gh": { "command": "npx", "args": ["-y", "@modelcontextprotocol/server-github"],
      "env": { "GITHUB_TOKEN": "a7f3c1e9d24b5f80" }, "trust": true } } }
CONF

payload = { config: CONFIG,
            surface: "settings",
            concern: "safety",
            context: "Gemini CLI 0.4, committed to the repo, shared by six engineers.",
            prescan_facts: { resources: [], flags: [] } }

est = api("POST", "/estimate", payload)
puts "worst case: #{est["hold_credits"] || est["credits"]} credits"
$config = <<<'CONF'
# file: .gemini/settings.json
{ "autoAccept": true, "coreTools": ["run_shell_command"],
  "mcpServers": { "gh": { "command": "npx", "args": ["-y", "@modelcontextprotocol/server-github"],
    "env": { "GITHUB_TOKEN": "a7f3c1e9d24b5f80" }, "trust": true } } }
CONF;

$payload = [
    "config"        => $config,
    "surface"       => "settings",
    "concern"       => "safety",
    "context"       => "Gemini CLI 0.4, committed to the repo, shared by six engineers.",
    "prescan_facts" => ["resources" => [], "flags" => []],
];

$est = api("POST", "/estimate", $payload);
echo "worst case: " . ($est["hold_credits"] ?? $est["credits"]) . " credits\n";
var config = """
    # file: .gemini/settings.json
    { "autoAccept": true, "coreTools": ["run_shell_command"],
      "mcpServers": { "gh": { "command": "npx", "args": ["-y", "@modelcontextprotocol/server-github"],
        "env": { "GITHUB_TOKEN": "a7f3c1e9d24b5f80" }, "trust": true } } }
    """;

var payload = new {
    config,
    surface = "settings",
    concern = "safety",
    context = "Gemini CLI 0.4, committed to the repo, shared by six engineers.",
    prescan_facts = new {
        resources = Array.Empty<object>(), flags = Array.Empty<object>(),
    },
};

var est = await SkillSafe.ApiAsync(HttpMethod.Post, "/estimate", payload);
Console.WriteLine($"worst case: {est.GetProperty("hold_credits")} credits");

prescan_facts.flags is how you make the review answer for things you already know about. Send {"resources": [{"id": "res:mcp/gh", "label": "MCPServer/gh"}], "flags": [{"id": "trusted-mcp:gh", "label": "gh runs with trust: true"}]} and every flag id comes back in coverage_check — addressed by a finding, or set aside with the reason. Nothing you flag is silently dropped, which makes it the field to assert on in a CI check.

Step 4 — Run the review and wait for the result

POST /run
GET /jobs/{job_id}

/run takes the same input as /estimate, places a credit hold and returns a job_id. Poll /jobs/{job_id} every 1–2 seconds until status is succeeded or failed (a run typically takes 30–90 s, since every finding carries a corrected JSON fragment and the reply also rebuilds the whole settings file). Always send an Idempotency-Key header so a network retry can't start a second, double-charged run — the app sends one on every run, and its automatic reformat retry reuses a key derived from the same input. The review is in output — usually nested as output.output, and as a JSON string, so parse defensively. The samples below print the posture, the inventory, the prioritized findings and the focus areas, save the whole object to review.json, and write corrected_settings out as a file you can drop into .gemini/.

JOB_ID=$(curl -s -X POST "$API/run" \
  -H "Authorization: Bearer $TOKEN" -H "Content-Type: application/json" \
  -H "Idempotency-Key: gc-$(date +%s)" \
  -d @input.json | jq -r '.data.job_id')

while :; do
  JOB=$(curl -s "$API/jobs/$JOB_ID" -H "Authorization: Bearer $TOKEN")
  STATUS=$(echo "$JOB" | jq -r '.data.status')
  [ "$STATUS" = "succeeded" ] || [ "$STATUS" = "failed" ] && break
  sleep 2
done

# unwrap the review once, then read it
echo "$JOB" | jq -r '.data.output.output' > review.json

jq -r '
  "\(.review_name) [\(.posture)]: \(.verdict)",
  "",
  "INVENTORY",
  (.inventory[] | "  \(.kind)/\(.name) in \(.scope) - \(.role)"),
  "",
  "FINDINGS",
  (.findings[] | "  [\(.priority)] \(.id) \(.category) \(.resource): \(.problem)"),
  "",
  "QUICK WINS",
  (.quick_wins[] | "  - \(.)"),
  "",
  "FOCUS AREAS",
  (.focus_areas[] | "  \(.area) - \(.why)"),
  "",
  "COVERAGE",
  (.coverage_check[] | "  \(.id): \(if .addressed then "ok" else "SET ASIDE" end) - \(.note)")' \
  review.json

# the headline artifact: a hardened, schema-migrated settings.json, ready to install
jq -r 'select(.corrected_settings != "") | .corrected_settings' review.json \
  > settings.hardened.json
jq empty settings.hardened.json && mv settings.hardened.json .gemini/settings.json

# fail the pipeline on anything critical
jq -e '[.findings[] | select(.priority == "critical")] | length == 0' review.json > /dev/null \
  || { echo "critical findings present"; exit 1; }
import time

job_id = api("POST", "/run", payload,
             **{"Idempotency-Key": "gc-001"})["job_id"]

while True:
    job = api("GET", f"/jobs/{job_id}")
    if job["status"] in ("succeeded", "failed"):
        break
    time.sleep(1.5)

if job["status"] == "failed":
    raise RuntimeError(job.get("error", "run failed"))

raw = job["output"]
if isinstance(raw, dict) and "output" in raw:
    raw = raw["output"]
review = json.loads(raw) if isinstance(raw, str) else raw

print(f'{review["review_name"]} [{review["posture"]}]: {review["verdict"]}')
for r in review["inventory"]:
    print(f'  {r["kind"]}/{r["name"]:<28} in={r["scope"] or "-":<24} {r["role"]}')
for f in review["findings"]:
    print(f'  [{f["priority"]:>8}] {f["id"]} {f["category"]} {f["resource"]}')
    print(f'      L:{f["likelihood"]}/S:{f["severity"]} {f["problem"]}')
    print(f'      fix: {f["fix"]}')
    if f["snippet"]:
        print("      snippet:", f["snippet"].splitlines()[0], "...")
for w in review["quick_wins"]:
    print("  win:", w)
for a in review["focus_areas"]:
    print(f'  focus {a["area"]} {a["finding_ids"]} - {a["why"]}')
for c in review["coverage_check"]:
    print(f'  {c["id"]}: {"ok" if c["addressed"] else "SET ASIDE"} - {c["note"]}')

with open("review.json", "w", encoding="utf-8") as fh:
    json.dump(review, fh, indent=2)

# the headline artifact: install it after checking it parses
if review["corrected_settings"]:
    json.loads(review["corrected_settings"])          # refuse to write invalid JSON
    with open("settings.hardened.json", "w", encoding="utf-8") as fh:
        fh.write(review["corrected_settings"])

critical = [f for f in review["findings"] if f["priority"] == "critical"]
if critical:
    raise SystemExit(f"{len(critical)} critical finding(s)")
import { writeFileSync } from "node:fs";

const { job_id } = await api("POST", "/run", payload,
  { "Idempotency-Key": crypto.randomUUID() });

let job;
do {
  await new Promise((r) => setTimeout(r, 1500));
  job = await api("GET", `/jobs/${job_id}`);
} while (job.status !== "succeeded" && job.status !== "failed");

if (job.status === "failed") throw new Error(job.error ?? "run failed");

const raw = job.output?.output ?? job.output;
const review = typeof raw === "string" ? JSON.parse(raw) : raw;

console.log(`${review.review_name} [${review.posture}]: ${review.verdict}`);
for (const r of review.inventory) {
  console.log(`  ${r.kind}/${r.name} (${r.scope || "-"}): ${r.role}`);
}
for (const f of review.findings) {
  console.log(`  [${f.priority}] ${f.id} ${f.category} ${f.resource}`);
  console.log(`      L:${f.likelihood}/S:${f.severity} - ${f.fix}`);
}
for (const w of review.quick_wins) console.log(`  win: ${w}`);
for (const a of review.focus_areas) {
  console.log(`  focus ${a.area} (${a.finding_ids.join(", ")}): ${a.why}`);
}
for (const c of review.coverage_check) {
  console.log(`  ${c.id}: ${c.addressed ? "ok" : "SET ASIDE"} - ${c.note}`);
}

writeFileSync("review.json", JSON.stringify(review, null, 2));

// the headline artifact: a settings.json you can install as-is
if (review.corrected_settings) {
  JSON.parse(review.corrected_settings); // refuse to write invalid JSON
  writeFileSync("settings.hardened.json", review.corrected_settings);
}

const critical = review.findings.filter((f) => f.priority === "critical");
if (critical.length) process.exitCode = 1;
var started struct{ JobID string `json:"job_id"` }
if err := call("POST", "/run", payload, &started); err != nil {
	log.Fatal(err)
}

var job struct {
	Status string          `json:"status"`
	Error  string          `json:"error"`
	Output json.RawMessage `json:"output"`
}
for {
	if err := call("GET", "/jobs/"+started.JobID, nil, &job); err != nil {
		log.Fatal(err)
	}
	if job.Status == "succeeded" || job.Status == "failed" {
		break
	}
	time.Sleep(1500 * time.Millisecond)
}

// job.Output is {"output": "<json string>"} — unwrap, then unmarshal:
type Review struct {
	ReviewName string `json:"review_name"`
	Posture    string `json:"posture"`
	Verdict    string `json:"verdict"`
	ExecSummary string `json:"exec_summary"`
	Assumptions   []string `json:"assumptions"`
	OpenQuestions []string `json:"open_questions"`
	Inventory []struct {
		Kind, Name, Scope, Role string
	} `json:"inventory"`
	Findings []struct {
		ID, Category, Severity, Likelihood, Priority string
		Resource, Problem, Impact, Fix, Snippet      string
	} `json:"findings"`
	CoverageCheck []struct {
		ID, Note  string
		Addressed bool
	} `json:"coverage_check"`
	CorrectedSettings string   `json:"corrected_settings"`
	QuickWins         []string `json:"quick_wins"`
	FocusAreas []struct {
		Area, Why  string
		FindingIDs []string `json:"finding_ids"`
	} `json:"focus_areas"`
	Summary string `json:"summary"`
}
var wrapper struct{ Output string `json:"output"` }
json.Unmarshal(job.Output, &wrapper)
var review Review
json.Unmarshal([]byte(wrapper.Output), &review)

fmt.Printf("%s [%s]: %s\n", review.ReviewName, review.Posture, review.Verdict)
for _, r := range review.Inventory {
	fmt.Printf("  %s/%s (%s): %s\n", r.Kind, r.Name, r.Scope, r.Role)
}
for _, f := range review.Findings {
	fmt.Printf("  [%s] %s %s %s: %s\n", f.Priority, f.ID, f.Category, f.Resource, f.Problem)
}
for _, a := range review.FocusAreas {
	fmt.Printf("  focus %s %v: %s\n", a.Area, a.FindingIDs, a.Why)
}
os.WriteFile("review.json", []byte(wrapper.Output), 0o644)

// the headline artifact: write it only if it really is JSON
if review.CorrectedSettings != "" && json.Valid([]byte(review.CorrectedSettings)) {
	os.WriteFile("settings.hardened.json", []byte(review.CorrectedSettings), 0o600)
}
String envelope = api("POST", "/run", jsonPayload);
String jobId = /* data.job_id via your JSON library */;

while (true) {
    String job = api("GET", "/jobs/" + jobId, null);
    String status = /* data.status */;
    if (status.equals("succeeded") || status.equals("failed")) break;
    Thread.sleep(1500);
}
// The review is at data.output.output as a JSON string — parse it again, then read
// review_name, posture, verdict, exec_summary, assumptions[], open_questions[],
// inventory[] (kind/name/scope/role),
// findings[] (id/category/severity/likelihood/priority/resource/problem/impact/fix/snippet),
// coverage_check[] (id/addressed/note), corrected_settings, quick_wins[],
// focus_areas[] (area/why/finding_ids[]) and summary.
// Finally keep the review on disk, and install the hardened settings file:
//   Files.writeString(Path.of("review.json"), reviewJson);
//   if (!correctedSettings.isEmpty())
//       Files.writeString(Path.of("settings.hardened.json"), correctedSettings);
started = api("POST", "/run", payload)

job = nil
loop do
  job = api("GET", "/jobs/#{started["job_id"]}")
  break if %w[succeeded failed].include?(job["status"])
  sleep 1.5
end
raise (job["error"] || "run failed") if job["status"] == "failed"

raw = job["output"].is_a?(Hash) ? job["output"].fetch("output", job["output"]) : job["output"]
review = raw.is_a?(String) ? JSON.parse(raw) : raw

puts "#{review["review_name"]} [#{review["posture"]}]: #{review["verdict"]}"
review["inventory"].each { |r| puts "  #{r["kind"]}/#{r["name"]} (#{r["scope"]}): #{r["role"]}" }
review["findings"].each do |f|
  puts "  [#{f["priority"]}] #{f["id"]} #{f["category"]} #{f["resource"]}"
  puts "      L:#{f["likelihood"]}/S:#{f["severity"]} - #{f["fix"]}"
end
review["quick_wins"].each { |w| puts "  win: #{w}" }
review["focus_areas"].each { |a| puts "  focus #{a["area"]} #{a["finding_ids"].join(", ")}" }
review["coverage_check"].each { |c| puts "  #{c["id"]}: #{c["addressed"] ? "ok" : "SET ASIDE"}" }

File.write("review.json", JSON.pretty_generate(review))

# the headline artifact
unless review["corrected_settings"].to_s.empty?
  JSON.parse(review["corrected_settings"])   # refuse to write invalid JSON
  File.write("settings.hardened.json", review["corrected_settings"])
end

exit 1 if review["findings"].any? { |f| f["priority"] == "critical" }
$started = api("POST", "/run", $payload);

do {
    sleep(2);
    $job = api("GET", "/jobs/" . $started["job_id"]);
} while (!in_array($job["status"], ["succeeded", "failed"]));

if ($job["status"] === "failed") {
    throw new Exception($job["error"] ?? "run failed");
}

$raw = is_array($job["output"]) ? ($job["output"]["output"] ?? $job["output"]) : $job["output"];
$review = is_string($raw) ? json_decode($raw, true) : $raw;

echo "{$review['review_name']} [{$review['posture']}]: {$review['verdict']}\n";
foreach ($review["inventory"] as $r) {
    echo "  {$r['kind']}/{$r['name']} ({$r['scope']}): {$r['role']}\n";
}
foreach ($review["findings"] as $f) {
    echo "  [{$f['priority']}] {$f['id']} {$f['category']} {$f['resource']}\n";
    echo "      L:{$f['likelihood']}/S:{$f['severity']} - {$f['fix']}\n";
}
foreach ($review["quick_wins"] as $w) {
    echo "  win: $w\n";
}
foreach ($review["focus_areas"] as $a) {
    echo "  focus {$a['area']}: " . implode(", ", $a["finding_ids"]) . "\n";
}
foreach ($review["coverage_check"] as $c) {
    echo "  {$c['id']}: " . ($c["addressed"] ? "ok" : "SET ASIDE") . "\n";
}

file_put_contents("review.json", json_encode($review, JSON_PRETTY_PRINT));

// the headline artifact
if (($review["corrected_settings"] ?? "") !== ""
    && json_decode($review["corrected_settings"], true) !== null) {
    file_put_contents("settings.hardened.json", $review["corrected_settings"]);
}
var started = await SkillSafe.ApiAsync(HttpMethod.Post, "/run", payload);
var jobId = started.GetProperty("job_id").GetString();

JsonElement job;
while (true)
{
    job = await SkillSafe.ApiAsync(HttpMethod.Get, $"/jobs/{jobId}");
    var status = job.GetProperty("status").GetString();
    if (status is "succeeded" or "failed") break;
    await Task.Delay(1500);
}

var rawText = job.GetProperty("output").GetProperty("output").GetString();
using var doc = JsonDocument.Parse(rawText!);
var review = doc.RootElement;

Console.WriteLine($"{review.GetProperty("review_name")} " +
                  $"[{review.GetProperty("posture")}]: {review.GetProperty("verdict")}");
foreach (var r in review.GetProperty("inventory").EnumerateArray())
{
    Console.WriteLine($"  {r.GetProperty("kind")}/{r.GetProperty("name")}: {r.GetProperty("role")}");
}
foreach (var f in review.GetProperty("findings").EnumerateArray())
{
    Console.WriteLine($"  [{f.GetProperty("priority")}] {f.GetProperty("id")} " +
                      $"{f.GetProperty("category")} {f.GetProperty("resource")} " +
                      $"(L:{f.GetProperty("likelihood")}/S:{f.GetProperty("severity")})");
}
foreach (var a in review.GetProperty("focus_areas").EnumerateArray())
{
    Console.WriteLine($"  focus {a.GetProperty("area")}: {a.GetProperty("why")}");
}

await File.WriteAllTextAsync("review.json", rawText!);

// the headline artifact
var hardened = review.GetProperty("corrected_settings").GetString();
if (!string.IsNullOrEmpty(hardened))
{
    using var _ = JsonDocument.Parse(hardened);   // refuse to write invalid JSON
    await File.WriteAllTextAsync("settings.hardened.json", hardened);
}

The model is asked for one JSON object and nothing else, but a stray code fence or preamble is always possible. Strip a leading ```json fence, take the text between the first { and the last }, and only then parse — that is what the app does before it falls back to a retry_note reformat run.

The review object — output schema

One JSON object, always the same shape. Every array is present, and the review is grounded in the pasted configuration alone: findings cite only settings, servers, commands and files that actually appear in config, and a key that is simply absent (no sandbox setting, no checkpointing, no tool allow-list, no context file at all) is reported against the nearest real key or against (missing from the config). Where the configuration is silent on something that changes the verdict you get an entry in assumptions and, if it would change the ranking, in open_questions. Expect five to fifteen findings on a typical setup — a carefully built one may honestly yield two or three, and findings is never empty.

FieldTypeMeaning
review_namestringA short title naming the setup, taken from the config's own naming — e.g. project .gemini/settings.json — configuration review.
posturestringproduction-ready | hardening-recommended | unsafe-as-configured. See the table below.
verdictstringOne sentence justifying the posture and naming the single most important change.
exec_summarystringTwo or three paragraphs, separated by blank lines, on the dominant themes across the configuration.
assumptionsstring[]Explicit assumptions filling gaps the config left open. Read these first — a wrong assumption invalidates the findings built on it.
open_questionsstring[]Questions whose answers would change the ranking.
inventoryarray{kind, name, scope, role} — every Setting, MCPServer, ContextFile, Command, Extension, Tool and Env entry the review parsed out of the paste and the part it plays. scope is the file or settings layer it is defined in — .gemini/settings.json, ~/.gemini/settings.json, an extension directory.
findingsarrayThe prioritized findings table — ids GC-001, GC-002, … in sequence, at least one entry. Columns are listed below.
coverage_checkarray{id, addressed, note} — one entry per prescan_facts.flags id you sent, each appearing exactly once. See the semantics below.
corrected_settingsstringThe headline artifact. A complete, hardened, schema-migrated settings.json as text — not a diff and not a fragment — carrying every fix the findings call for, deprecated flat keys moved into their current nested homes, secrets replaced with $VAR references, and MCP servers pinned and untrusted. Write it straight to .gemini/settings.json. Empty string ("") when no settings file was pasted — a paste of only a GEMINI.md or a command .toml gets its corrections in the per-finding snippet fields instead.
quick_winsstring[]One-line changes worth doing immediately, ahead of any planning. May be empty when nothing here is a one-liner.
focus_areasarray{area, why, finding_ids} — what to work through first, one sentence tied to the review, and the finding ids that motivate it. Every id in finding_ids exists in findings.
summarystringClosing paragraph: what to fix first, and what risk remains after that.

The three posture values:

postureWhat it means
production-readyThe configuration holds up as written: every tool-approving switch is deliberate and narrow, the sandbox and folder-trust settings are on, MCP servers are pinned and untrusted, secrets arrive by reference, and the context file is current and within budget. Findings still exist, but they are additions and refinements — a tighter allow-list, telemetry routing, a namespaced command directory — not blockers. Genuinely well-built setups land here rather than having severity manufactured for them.
hardening-recommendedThe shape is right, but named gaps should be closed before this config is shared or committed — a deny-list where an allow-list belongs, checkpointing left off while the write tools are enabled, an unpinned npx -y server, a context file that has drifted from the codebase.
unsafe-as-configuredAt least one setting hands the model or a third party more than the author can have intended: auto-approval or YOLO mode combined with shell and write tools, trust: true on a server that skips every confirmation prompt, a live credential written inline in env, a committed command file whose !{...} block runs on someone else's machine, or the sandbox disabled while the model may run arbitrary commands.

Each entry in findings:

ColumnMeaning
idSequential GC-001, GC-002, … — the stable handle referenced from focus_areas[].finding_ids.
categorysafety | correctness | context-quality | tooling | cost | hygiene. Weighted by the concern you sent, but never restricted to it.
severitylow | medium | high — how bad it is when it bites.
likelihoodlow | medium | high — how likely it is to bite.
prioritycritical | high | medium | low — severity by likelihood. critical is reserved for a setting that removes the human from a destructive loop (auto-approval with shell access, a trusted server with no confirmation) or leaks a credential, so sort on this field and work top-down. This is also the field to gate a pipeline on.
resourceThe Setting/tools.sandbox, MCPServer/gh, ContextFile/GEMINI.md, Command/deploy or file this is about — always something that appears in config, or the literal (missing from the config) when the finding is about an absent key.
problemWhat is wrong, in this configuration specifically.
impactWhat the CLI actually does because of it, and what that costs the team.
fixThe concrete change to make — the key, the value, the layer — not "review your permissions".
snippetA corrected JSON, TOML or Markdown fragment you can paste: the fixed block, correctly indented, matching the file it belongs to, not the whole file (that is corrected_settings). Empty string when a snippet would add nothing. Secret values are never echoed — a $VAR reference or a placeholder appears instead.

coverage_check semantics:

CaseWhat you get
Every flag id you sentEach prescan_facts.flags id appears in coverage_check exactly once. Nothing you flagged is silently dropped, which makes this the field to assert on in a CI check. Ids in prescan_facts.resources are not reconciled here — they shape the inventory instead.
addressed: trueThe flag is covered by the review; note names the finding id that covers it.
addressed: falseThe flag was deliberately set aside; note gives the reason — a check that fired but is not a real problem for this setup (a trust: true on a first-party server that only reads an internal read-only index, telemetry left on inside a config that never leaves a sandboxed lab machine).
Nothing sentOmit prescan_facts, or send the two empty arrays, and coverage_check comes back empty. The rest of the review is unaffected.

A small, realistic result for the snippet above, trimmed for length:

{
  "review_name": "project .gemini/settings.json — configuration review",
  "posture": "unsafe-as-configured",
  "verdict": "autoAccept plus an unrestricted run_shell_command and a trusted MCP server means
              the model can run any command on any machine that opens this repo; scope the
              tools and drop trust before this file is committed again.",
  "exec_summary": "Three settings compound into one problem: every confirmation prompt has been
                   removed. autoAccept approves tool calls without asking, run_shell_command is
                   enabled with no argument restriction, and the gh server is marked trusted so
                   its tools skip confirmation too. Any of the three alone would be a finding;
                   together they leave nothing between a model suggestion and a shell.

                   The second theme is distribution. This file is committed, so it is not one
                   engineer's preference — it is the default for everyone who clones the repo,
                   including the inline GITHUB_TOKEN, which is now in version control and must be
                   rotated rather than merely removed.

                   The keys themselves are also a schema generation behind: autoAccept and
                   coreTools are flat legacy names. Current builds read tools.core and an
                   approval mode, so parts of this file may already be silently ignored — the
                   config is not doing what its author believes it does.",
  "assumptions": [
    "This is the project-level .gemini/settings.json, since no home-directory path was given.",
    "GITHUB_TOKEN holds a live credential, since it is a literal opaque value rather than a $VAR reference.",
    "No sandbox is configured anywhere else, since tools.sandbox does not appear."
  ],
  "open_questions": [
    "Is this file committed to the repository, or ignored and local to one machine?",
    "Which Gemini CLI version does the team run — the flat keys are read by older builds only?"
  ],
  "inventory": [
    { "kind": "Setting", "name": "autoAccept", "scope": ".gemini/settings.json",
      "role": "Legacy flat switch that approves tool calls without a confirmation prompt." },
    { "kind": "Setting", "name": "coreTools", "scope": ".gemini/settings.json",
      "role": "Legacy allow-list of built-in tools; here it enables the shell tool wholesale." },
    { "kind": "Tool", "name": "run_shell_command", "scope": "coreTools",
      "role": "Runs arbitrary shell commands with no argument restriction." },
    { "kind": "MCPServer", "name": "gh", "scope": ".gemini/settings.json",
      "role": "GitHub MCP server started through npx, marked trusted, unpinned." },
    { "kind": "Env", "name": "GITHUB_TOKEN", "scope": "mcpServers.gh.env",
      "role": "Credential passed to the gh server, written inline as a literal." }
  ],
  "findings": [
    { "id": "GC-001", "category": "safety",
      "severity": "high", "likelihood": "high", "priority": "critical",
      "resource": "Setting/autoAccept",
      "problem": "autoAccept is true while run_shell_command is enabled with no argument
                 restriction, so shell calls execute with no confirmation.",
      "impact": "One bad suggestion — a stray rm, a git reset --hard, a curl piped to a shell —
                 runs immediately on the developer's machine, with their credentials, and there
                 is no prompt at which anyone could stop it.",
      "fix": "Remove autoAccept and let the default prompting mode stand; if some commands must
              be non-interactive, allow those exact commands instead of the whole tool.",
      "snippet": "{\n  \"tools\": {\n    \"core\": [\n      \"read_file\",\n      \"write_file\",\n      \"run_shell_command(git status)\",\n      \"run_shell_command(npm test)\"\n    ]\n  }\n}" },
    { "id": "GC-002", "category": "safety",
      "severity": "high", "likelihood": "high", "priority": "critical",
      "resource": "Env/GITHUB_TOKEN",
      "problem": "A live GitHub token is written inline in mcpServers.gh.env instead of being
                 referenced from the environment.",
      "impact": "The credential is in the file, and therefore in git history and in every clone
                 and fork. Deleting the line does not undo it: the token has to be rotated.",
      "fix": "Rotate the token now, then reference it as $GITHUB_TOKEN so the value lives in your
              shell or .env and never in the committed config.",
      "snippet": "{\n  \"mcpServers\": {\n    \"gh\": {\n      \"env\": { \"GITHUB_TOKEN\": \"$GITHUB_TOKEN\" }\n    }\n  }\n}" },
    { "id": "GC-003", "category": "safety",
      "severity": "high", "likelihood": "medium", "priority": "high",
      "resource": "MCPServer/gh",
      "problem": "trust: true tells the CLI to skip the confirmation prompt for every tool this
                 server exposes, including write operations on repositories.",
      "impact": "A prompt-injected instruction reaching the model — from an issue body, a PR
                 comment, a fetched page — can open, close or comment on real GitHub objects with
                 no human in the loop.",
      "fix": "Set trust to false and, if the prompting is too noisy, narrow the surface with
              includeTools instead.",
      "snippet": "{\n  \"mcpServers\": {\n    \"gh\": {\n      \"trust\": false,\n      \"includeTools\": [\"list_issues\", \"get_pull_request\"],\n      \"timeout\": 30000\n    }\n  }\n}" },
    { "id": "GC-004", "category": "correctness",
      "severity": "medium", "likelihood": "high", "priority": "high",
      "resource": "Setting/coreTools",
      "problem": "autoAccept and coreTools are flat keys from the pre-migration schema; current
                 builds read tools.core and the approval mode under general.",
      "impact": "On a recent CLI these keys may be ignored entirely, so the file neither restricts
                 tools as written nor behaves as the author expects — the real behaviour depends
                 on which version each engineer has installed.",
      "fix": "Migrate to the nested schema and add the $schema reference so an editor validates
              the file as you edit it.",
      "snippet": "{\n  \"$schema\": \"https://raw.githubusercontent.com/google-gemini/gemini-cli/main/packages/cli/src/config/settingsSchema.json\",\n  \"tools\": { \"core\": [\"read_file\"] }\n}" },
    { "id": "GC-005", "category": "safety",
      "severity": "medium", "likelihood": "medium", "priority": "medium",
      "resource": "(missing from the config)",
      "problem": "No tools.sandbox, no security.folderTrust and no general.checkpointing, so file
                 edits and commands run directly on the host with no undo point.",
      "impact": "There is no boundary between a mistaken edit and your working tree, and nothing
                 to roll back to after one.",
      "fix": "Turn on the docker sandbox, enable folder trust so an untrusted clone cannot supply
              its own settings, and enable checkpointing so edits can be reverted.",
      "snippet": "{\n  \"general\": { \"checkpointing\": { \"enabled\": true } },\n  \"tools\": { \"sandbox\": \"docker\" },\n  \"security\": { \"folderTrust\": { \"enabled\": true } }\n}" },
    { "id": "GC-006", "category": "hygiene",
      "severity": "low", "likelihood": "medium", "priority": "low",
      "resource": "MCPServer/gh",
      "problem": "npx -y @modelcontextprotocol/server-github resolves to whatever version is
                 newest at launch time, with install prompts suppressed.",
      "impact": "The code that gets your token changes without any change to your repository, and
                 two engineers can be running different builds on the same day.",
      "fix": "Pin an exact version in args, and give the server an explicit timeout.",
      "snippet": "{\n  \"mcpServers\": {\n    \"gh\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@modelcontextprotocol/server-github@0.6.2\"]\n    }\n  }\n}" }
  ],
  "coverage_check": [
    { "id": "auto-accept:autoAccept", "addressed": true, "note": "GC-001." },
    { "id": "inline-secret:mcpServers.gh.env.GITHUB_TOKEN", "addressed": true, "note": "GC-002." },
    { "id": "trusted-mcp:gh", "addressed": true, "note": "GC-003." },
    { "id": "deprecated-key:coreTools", "addressed": true, "note": "GC-004." },
    { "id": "unpinned-mcp:gh", "addressed": true, "note": "GC-006." }
  ],
  "corrected_settings": "{\n  \"$schema\": \"https://raw.githubusercontent.com/google-gemini/gemini-cli/main/packages/cli/src/config/settingsSchema.json\",\n  \"general\": {\n    \"checkpointing\": { \"enabled\": true }\n  },\n  \"tools\": {\n    \"sandbox\": \"docker\",\n    \"core\": [\n      \"read_file\",\n      \"write_file\",\n      \"run_shell_command(git status)\",\n      \"run_shell_command(npm test)\"\n    ]\n  },\n  \"security\": {\n    \"folderTrust\": { \"enabled\": true }\n  },\n  \"mcpServers\": {\n    \"gh\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@modelcontextprotocol/server-github@0.6.2\"],\n      \"env\": { \"GITHUB_TOKEN\": \"$GITHUB_TOKEN\" },\n      \"includeTools\": [\"list_issues\", \"get_pull_request\"],\n      \"trust\": false,\n      \"timeout\": 30000\n    }\n  }\n}",
  "quick_wins": [
    "Delete the autoAccept line — the default prompting mode is the safe one.",
    "Replace the inline token with \"$GITHUB_TOKEN\" and rotate the old value today.",
    "Add the $schema line so your editor flags legacy keys as you type."
  ],
  "focus_areas": [
    { "area": "Put a human back in the destructive loop",
      "why": "Auto-approval, an unrestricted shell tool and a trusted server together remove
              every confirmation this config could have offered.",
      "finding_ids": ["GC-001", "GC-003"] },
    { "area": "Get the credential out of the repository",
      "why": "An inline token in a committed file is already leaked; only rotation closes it.",
      "finding_ids": ["GC-002"] },
    { "area": "Migrate to the current schema",
      "why": "Legacy flat keys may be silently ignored, so the file's real behaviour is unknown.",
      "finding_ids": ["GC-004", "GC-005"] }
  ],
  "summary": "Rotate the GitHub token, then install corrected_settings as-is: it drops
              auto-approval, narrows run_shell_command to two named commands, untrusts and pins
              the gh server, and turns on the sandbox, folder trust and checkpointing. After that
              the remaining risk is scope creep in the allow-list — revisit it whenever a new
              command is added, and keep the file under review like any other committed
              permission grant."
}

corrected_settings is the artifact to automate on: it is a whole file, so a pipeline can write it to .gemini/settings.json, run jq empty or your JSON validator over it, and open a pull request with the diff. Parse it before you install it — it is a string in the reply, not a nested object — and read the findings that produced it, because narrowing a tool allow-list can legitimately break a workflow that relied on the wider grant.

This is AI-generated review from configuration text, not a security sign-off: it sees only what you sent, never a real CLI session, the MCP servers themselves or the rest of your environment. Check assumptions and open_questions before you act on the rankings, validate every snippet and the rebuilt settings file before installing them, and keep a human reviewer in the loop.

Step 5 — Stream the review as it is written

POST /run-stream

/run-stream takes exactly the same body as /run but answers with server-sent events, so you can show progress instead of a spinner — useful here because a full findings table plus a rebuilt settings file makes for a long reply. This app's own progress panel is this endpoint. Events are separated by a blank line; each has an event: line and a data: line carrying JSON.

EventPayloadMeaning
job{job_id, status}Sent once, when the job is accepted — show "starting".
delta{text}A chunk of the reply, in order. Append it; the accumulated length is your only progress signal (the total is not known in advance). The app advances its step list by watching for the "review_name", "inventory", "findings", "coverage_check", "corrected_settings" and "focus_areas" keys as they arrive.
done{job_id, status, charged_credits, output}The final, authoritative result — read the review from output.output rather than trusting concatenated deltas, and the settled price from charged_credits.
error{code, message}Replaces done when the run fails.
# -N disables buffering so events print as they arrive
curl -N -s -X POST "$API/run-stream" \
  -H "Authorization: Bearer $TOKEN" -H "Content-Type: application/json" \
  -H "Idempotency-Key: gc-$(date +%s)" \
  -d @input.json

# event: job
# data: {"job_id":"job_...","status":"running"}
#
# event: delta
# data: {"text":"{\"review_name\":\"project"}
# ...
# event: done
# data: {"job_id":"job_...","status":"succeeded","charged_credits":612,"output":{"output":"{...}"}}
import json, requests

result = None
with requests.post(
    API + "/run-stream",
    headers={"Authorization": f"Bearer {TOKEN}",
             "Idempotency-Key": "gc-001"},
    json=payload,
    stream=True,
) as r:
    r.raise_for_status()
    event = None
    for line in r.iter_lines(decode_unicode=True):
        if not line:
            continue
        if line.startswith("event:"):
            event = line[len("event:"):].strip()
        elif line.startswith("data:"):
            data = json.loads(line[len("data:"):].strip())
            if event == "delta":
                print(".", end="", flush=True)          # live progress
            elif event == "done":
                result = data
            elif event == "error":
                raise RuntimeError(data.get("message", "run failed"))

review = json.loads(result["output"]["output"])          # authoritative
print("charged:", result["charged_credits"], "-", review["review_name"])
print("posture:", review["posture"])
for f in review["findings"]:
    print(f'  [{f["priority"]}] {f["id"]} {f["resource"]}: {f["problem"]}')
with open("review.json", "w", encoding="utf-8") as fh:
    json.dump(review, fh, indent=2)
if review["corrected_settings"]:
    with open("settings.hardened.json", "w", encoding="utf-8") as fh:
        fh.write(review["corrected_settings"])
const res = await fetch(API + "/run-stream", {
  method: "POST",
  headers: {
    Authorization: `Bearer ${TOKEN}`,
    "Content-Type": "application/json",
    "Idempotency-Key": crypto.randomUUID(),
  },
  body: JSON.stringify(payload),
});

const reader = res.body.getReader();
const decoder = new TextDecoder();
let buf = "", done = null;

for (;;) {
  const chunk = await reader.read();
  if (chunk.done) break;
  buf += decoder.decode(chunk.value, { stream: true });
  const frames = buf.split("\n\n");
  buf = frames.pop();
  for (const frame of frames) {
    const name = /^event:\s*(.+)$/m.exec(frame)?.[1];
    const body = /^data:\s*(.+)$/m.exec(frame)?.[1];
    if (!name || !body) continue;
    const data = JSON.parse(body);
    if (name === "delta") process.stdout.write(".");   // live progress
    if (name === "done") done = data;
    if (name === "error") throw new Error(data.message ?? "run failed");
  }
}

const review = JSON.parse(done.output.output);
console.log(`\n${done.charged_credits} credits - ${review.review_name} [${review.posture}]`);
for (const f of review.findings) console.log(`  [${f.priority}] ${f.id} ${f.resource}`);
writeFileSync("review.json", JSON.stringify(review, null, 2));
if (review.corrected_settings) {
  writeFileSync("settings.hardened.json", review.corrected_settings);
}
body, _ := json.Marshal(payload)
req, _ := http.NewRequest("POST", API+"/run-stream", bytes.NewReader(body))
req.Header.Set("Authorization", "Bearer "+token)
req.Header.Set("Content-Type", "application/json")
req.Header.Set("Idempotency-Key", "gc-001")

res, err := http.DefaultClient.Do(req)
if err != nil {
	log.Fatal(err)
}
defer res.Body.Close()

var event string
var final map[string]any
sc := bufio.NewScanner(res.Body)
sc.Buffer(make([]byte, 0, 64*1024), 4*1024*1024)
for sc.Scan() {
	line := sc.Text()
	switch {
	case strings.HasPrefix(line, "event:"):
		event = strings.TrimSpace(strings.TrimPrefix(line, "event:"))
	case strings.HasPrefix(line, "data:"):
		var data map[string]any
		json.Unmarshal([]byte(strings.TrimPrefix(line, "data:")), &data)
		switch event {
		case "delta":
			fmt.Print(".") // live progress
		case "done":
			final = data
		case "error":
			log.Fatal(data["message"])
		}
	}
}
// final["output"].(map[string]any)["output"].(string) is the review JSON — unmarshal it
// into the Review struct from step 4, write it to review.json, and write
// review.CorrectedSettings to settings.hardened.json when it is not empty.
// Java 17+ — read the stream line by line instead of buffering the body.
var req = HttpRequest.newBuilder(URI.create(API + "/run-stream"))
    .header("Authorization", "Bearer " + TOKEN)
    .header("Content-Type", "application/json")
    .header("Idempotency-Key", "gc-001")
    .POST(HttpRequest.BodyPublishers.ofString(jsonPayload))
    .build();

var res = HTTP.send(req, HttpResponse.BodyHandlers.ofLines());
String event = null, done = null;
for (String line : (Iterable<String>) res.body()::iterator) {
    if (line.startsWith("event:")) {
        event = line.substring(6).trim();
    } else if (line.startsWith("data:")) {
        String data = line.substring(5).trim();
        if ("delta".equals(event)) System.out.print(".");   // live progress
        else if ("done".equals(event)) done = data;
        else if ("error".equals(event)) throw new RuntimeException(data);
    }
}
// parse `done`, then parse data.output.output again — it is a JSON string holding
// review_name, posture, verdict, inventory[], findings[], coverage_check[],
// corrected_settings, quick_wins[], focus_areas[] and the rest.
require "net/http"
require "json"

uri = URI(API + "/run-stream")
req = Net::HTTP::Post.new(uri)
req["Authorization"] = "Bearer #{TOKEN}"
req["Content-Type"] = "application/json"
req["Idempotency-Key"] = "gc-001"
req.body = payload.to_json

event = nil
done = nil
Net::HTTP.start(uri.host, uri.port, use_ssl: true) do |http|
  http.request(req) do |res|
    res.read_body do |chunk|
      chunk.each_line do |line|
        line = line.strip
        if line.start_with?("event:")
          event = line.delete_prefix("event:").strip
        elsif line.start_with?("data:")
          data = JSON.parse(line.delete_prefix("data:").strip)
          case event
          when "delta" then print "."           # live progress
          when "done"  then done = data
          when "error" then raise (data["message"] || "run failed")
          end
        end
      end
    end
  end
end

review = JSON.parse(done["output"]["output"])
puts "\n#{done["charged_credits"]} credits - #{review["review_name"]} [#{review["posture"]}]"
review["findings"].each { |f| puts "  [#{f["priority"]}] #{f["id"]} #{f["resource"]}" }
File.write("review.json", JSON.pretty_generate(review))
File.write("settings.hardened.json", review["corrected_settings"]) unless
  review["corrected_settings"].to_s.empty?
$event = null;
$done  = null;

$ch = curl_init(API . "/run-stream");
curl_setopt_array($ch, [
    CURLOPT_POST       => true,
    CURLOPT_HTTPHEADER => [
        "Authorization: Bearer $TOKEN",
        "Content-Type: application/json",
        "Idempotency-Key: gc-001",
    ],
    CURLOPT_POSTFIELDS => json_encode($payload),
    CURLOPT_WRITEFUNCTION => function ($ch, $chunk) use (&$event, &$done) {
        foreach (explode("\n", $chunk) as $line) {
            $line = trim($line);
            if (str_starts_with($line, "event:")) {
                $event = trim(substr($line, 6));
            } elseif (str_starts_with($line, "data:")) {
                $data = json_decode(trim(substr($line, 5)), true);
                if ($event === "delta") { echo "."; }        // live progress
                elseif ($event === "done") { $done = $data; }
                elseif ($event === "error") { throw new Exception($data["message"] ?? "run failed"); }
            }
        }
        return strlen($chunk);
    },
]);
curl_exec($ch);
curl_close($ch);

$review = json_decode($done["output"]["output"], true);
echo "\n{$done['charged_credits']} credits - {$review['review_name']} [{$review['posture']}]\n";
foreach ($review["findings"] as $f) {
    echo "  [{$f['priority']}] {$f['id']} {$f['resource']}\n";
}
file_put_contents("review.json", json_encode($review, JSON_PRETTY_PRINT));
if (($review["corrected_settings"] ?? "") !== "") {
    file_put_contents("settings.hardened.json", $review["corrected_settings"]);
}
var req = new HttpRequestMessage(HttpMethod.Post, Api + "/run-stream") {
    Content = JsonContent.Create(payload),
};
req.Headers.Add("Idempotency-Key", "gc-001");

using var res = await Http.SendAsync(req, HttpCompletionOption.ResponseHeadersRead);
using var reader = new StreamReader(await res.Content.ReadAsStreamAsync());

string? evt = null, done = null;
while (await reader.ReadLineAsync() is { } line)
{
    if (line.StartsWith("event:")) evt = line[6..].Trim();
    else if (line.StartsWith("data:"))
    {
        var data = line[5..].Trim();
        if (evt == "delta") Console.Write(".");            // live progress
        else if (evt == "done") done = data;
        else if (evt == "error") throw new Exception(data);
    }
}

using var final = JsonDocument.Parse(done!);
var text = final.RootElement.GetProperty("output").GetProperty("output").GetString();
using var reviewDoc = JsonDocument.Parse(text!);
var review = reviewDoc.RootElement;
Console.WriteLine($"{review.GetProperty("review_name")} [{review.GetProperty("posture")}]");
foreach (var f in review.GetProperty("findings").EnumerateArray())
    Console.WriteLine($"  [{f.GetProperty("priority")}] {f.GetProperty("id")} {f.GetProperty("resource")}");
await File.WriteAllTextAsync("review.json", text!);
var hardened = review.GetProperty("corrected_settings").GetString();
if (!string.IsNullOrEmpty(hardened))
    await File.WriteAllTextAsync("settings.hardened.json", hardened);

In a browser, the native EventSource only speaks GET, and this endpoint is a POST — read the fetch response body incrementally, as the JavaScript sample above does. On an idempotent replay the server may answer with a plain JSON envelope instead of an event stream; check the Content-Type before you start parsing frames.