deploy-to-gcp-serverless
Warn
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONCREDENTIALS_UNSAFE
Full Analysis
- [DATA_EXFILTRATION]: The
scripts/setup-gcp.shscript configures the Cloud Storage bucket to be publicly readable by grantingroles/storage.objectViewertoallUsers. This exposure allows any internet user to read data uploaded to the bucket, which may lead to unintended data leaks. - [COMMAND_EXECUTION]: The skill instructs the agent to execute bash scripts (
setup-gcp.sh,deploy.sh) using environment variables likeAPP_NAMEandGCP_PROJECT_IDprovided by the user. These variables are interpolated into shell commands without sanitization, creating a surface for command injection if malicious input is provided. 1. Ingestion points:APP_NAMEandGCP_PROJECT_IDvariables inSKILL.md. 2. Boundary markers: None identified. 3. Capability inventory:gcloudCLI commands,dockerbuild/push, and sub-shell execution viabash. 4. Sanitization: No validation or escaping is performed on user-provided project or app names before shell interpolation. - [CREDENTIALS_UNSAFE]: Although the skill correctly utilizes GCP Secret Manager for persistence, the
scripts/setup-gcp.shscript prints the generated database password to the terminal's standard output. This practice risks exposing sensitive credentials in terminal history or logs.
Audit Metadata