gcp-resource-optimizer

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides legitimate documentation, SQL queries, and CLI templates for optimizing Google Cloud Platform resources.
  • [COMMAND_EXECUTION]: The skill uses gcloud CLI commands to audit usage and manage budgets, which is consistent with its stated purpose of cloud resource optimization.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides a surface for indirect prompt injection via user-provided identifiers (e.g., ACCOUNT_ID, PROJECT_ID) used in shell command templates. * Ingestion points: User-supplied parameters for gcloud commands in SKILL.md. * Boundary markers: Not explicitly provided in the command templates. * Capability inventory: Shell execution via gcloud and BigQuery query execution. * Sanitization: No sanitization logic is included in the instructions. Agents should validate these inputs to prevent command injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 06:53 PM
Security Audit — agent-trust-hub — gcp-resource-optimizer