god-iam-gcp
Pass
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns, obfuscation, or unauthorized data access commands were detected across the analyzed skill files.
- [PROMPT_INJECTION]: The skill implements robust anti-hallucination rules and operating principles to ensure accuracy and prevent behavioral drift. The analysis of the indirect prompt injection surface is as follows:
- Ingestion points: User-provided code and architecture descriptions are processed via the prompt library in 'prompts/examples.md'.
- Boundary markers: The instructions lack explicit data delimiters for user input, relying instead on the agent's internal persona constraints and domain rules.
- Capability inventory: The skill utilizes powerful 'gcloud' CLI commands for IAM policy analysis and modification as listed in 'SKILL.md'.
- Sanitization: No explicit input sanitization is defined for user-supplied data, though the persona is instructed to verify all assertions against official documentation.
- [EXTERNAL_DOWNLOADS]: All external references point to official Google Cloud documentation and trusted repositories (e.g., cloud.google.com), which are categorized as safe sources and do not escalate the verdict.
- [COMMAND_EXECUTION]: The skill provides numerous 'gcloud' CLI command examples for GCP IAM management. These are educational in nature and intended for authorized agent use in a controlled environment or manual execution by the user.
Audit Metadata