Gemini Clinic — Gemini CLI settings, GEMINI.md & MCP review
Paste your Gemini CLI setup — .gemini/settings.json, GEMINI.md, custom slash-command TOML, a gemini-extension.json manifest — and get a senior platform engineer's configuration review: a safety posture (production-ready / hardening-recommended / unsafe-as-configured), the inventory of every setting, MCP server, context file, command and tool, prioritized findings with corrected JSON, and the whole settings.json handed back hardened and migrated off the deprecated pre-0.29 flat keys. A free instant prescan parses the files in your browser first — real JSON, TOML and Markdown parsing — and flags literal credentials, autoAccept and yolo approval modes, MCP servers marked trust:true, unpinned npx launches, plaintext endpoints, run_shell_command wildcards, a missing tool allow-list, sandboxing and checkpointing off, prompt logging, deprecated and unknown keys, invalid JSON, context loaded from outside the project, bloated or unenforceable GEMINI.md rules and {{args}} inside a shell block. Derived from @google-gemini/gemini-cli (Apache-2.0); not affiliated with Google.
Details
gpt-terra Every public app is built from a security-scanned skill and must pass a clean scan — skill and frontend — before it can be listed. Have a skill of your own? Turn it into an app — or read the step-by-step walkthrough.