broccoli-oss-gcp-deploy

Fail

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: HIGHCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses subprocess.run to execute multiple external binaries and shell scripts, including gcloud, docker, envsubst, and repository-local deployment scripts.
  • Evidence in scripts/_common.py: The run_command function serves as a wrapper for executing system commands with captured output.
  • Evidence in scripts/deploy.py: The deployment logic directly invokes deploy/build-and-push.sh and deploy/bootstrap.sh from the repository root.
  • [REMOTE_CODE_EXECUTION]: The skill is instructed to clone a repository from a user-supplied URL and immediately proceed to execute shell scripts found within that repository.
  • Evidence in SKILL.md: "If they only provided the GitHub repo URL, clone the repo first, then use this skill from the repo checkout."
  • [DATA_EXFILTRATION]: The skill fetches highly sensitive credentials from GCP Secret Manager for use in discovery and third-party API interactions.
  • Evidence in scripts/deploy.py: The script retrieves broccoli-oss-github-app-private-key-pem, broccoli-oss-linear-api-key, and other secrets via the gcloud secrets versions access command.
  • Evidence in scripts/deploy.py: Sensitive private keys are used to sign JWTs for GitHub authentication, and API keys are transmitted to the Linear GraphQL API.
  • [DYNAMIC_EXECUTION]: The skill assembles shell scripts at runtime and executes them within a temporary Cloud Run Job environment.
  • Evidence in scripts/deploy.py: The build_seed_yaml function generates configuration which is then passed into a shell heredoc for execution via execute_operator_job_command.
  • Evidence in scripts/deploy.py: The create_temporary_operator_job function configures a Cloud Run job to execute arbitrary commands passed as arguments.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a high vulnerability surface for indirect injection as it ingests entire repositories while maintaining extensive system and cloud capabilities.
  • Ingestion points: Repository content cloned from user-supplied URLs as specified in SKILL.md.
  • Boundary markers: None; the instructions do not include safeguards against malicious instructions within the cloned repository.
  • Capability inventory: Shell command execution in scripts/_common.py, network access to third-party APIs in scripts/deploy.py, IAM policy management, and Cloud SQL/Secret Manager operations in scripts/deploy.py.
  • Sanitization: No validation or sanitization is performed on the scripts or configuration files within the cloned repository before they are executed.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 8, 2026, 10:46 AM
Security Audit — agent-trust-hub — broccoli-oss-gcp-deploy