Please report security issues privately through GitHub Security Advisories rather than opening a public issue.
- Your prompts and images go to Google. Every prompt, and every image
passed to
edit_imageoranalyze_design, is uploaded to the Gemini API. Your.gemini-design-profile.jsoncontents (colors, fonts, framework) are injected into prompts and sent too. - One outbound host.
generativelanguage.googleapis.com, via thegoogle-genaiSDK. There is no telemetry, no analytics, and no first-party backend. - Your API key is read from the
GEMINI_API_KEYenvironment variable. It is never logged — the startup line records only[set]or[missing]. - Local files. Generated assets and metadata sidecars are written to
~/.cache/gemini-visual-design/preview/and pruned after 7 days.save_assetcopies into a directory you name; the destination is constrained to your project root and the filename must be a bare filename with no path separators.
The plugin executes no user-supplied code and spawns no subprocesses. The
main risk surface is filesystem writes via save_asset and
init_style_profile, and prompt content reaching a third party.