deploy-to-gcp-serverless

Warn

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONCREDENTIALS_UNSAFE
Full Analysis
  • [DATA_EXFILTRATION]: The scripts/setup-gcp.sh script configures the Cloud Storage bucket to be publicly readable by granting roles/storage.objectViewer to allUsers. This exposure allows any internet user to read data uploaded to the bucket, which may lead to unintended data leaks.
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute bash scripts (setup-gcp.sh, deploy.sh) using environment variables like APP_NAME and GCP_PROJECT_ID provided by the user. These variables are interpolated into shell commands without sanitization, creating a surface for command injection if malicious input is provided. 1. Ingestion points: APP_NAME and GCP_PROJECT_ID variables in SKILL.md. 2. Boundary markers: None identified. 3. Capability inventory: gcloud CLI commands, docker build/push, and sub-shell execution via bash. 4. Sanitization: No validation or escaping is performed on user-provided project or app names before shell interpolation.
  • [CREDENTIALS_UNSAFE]: Although the skill correctly utilizes GCP Secret Manager for persistence, the scripts/setup-gcp.sh script prints the generated database password to the terminal's standard output. This practice risks exposing sensitive credentials in terminal history or logs.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 16, 2026, 10:31 AM
Security Audit — agent-trust-hub — deploy-to-gcp-serverless