broccoli-oss-gcp-deploy
Fail
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: HIGHCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
subprocess.runto execute multiple external binaries and shell scripts, includinggcloud,docker,envsubst, and repository-local deployment scripts. - Evidence in
scripts/_common.py: Therun_commandfunction serves as a wrapper for executing system commands with captured output. - Evidence in
scripts/deploy.py: The deployment logic directly invokesdeploy/build-and-push.shanddeploy/bootstrap.shfrom the repository root. - [REMOTE_CODE_EXECUTION]: The skill is instructed to clone a repository from a user-supplied URL and immediately proceed to execute shell scripts found within that repository.
- Evidence in
SKILL.md: "If they only provided the GitHub repo URL, clone the repo first, then use this skill from the repo checkout." - [DATA_EXFILTRATION]: The skill fetches highly sensitive credentials from GCP Secret Manager for use in discovery and third-party API interactions.
- Evidence in
scripts/deploy.py: The script retrievesbroccoli-oss-github-app-private-key-pem,broccoli-oss-linear-api-key, and other secrets via thegcloud secrets versions accesscommand. - Evidence in
scripts/deploy.py: Sensitive private keys are used to sign JWTs for GitHub authentication, and API keys are transmitted to the Linear GraphQL API. - [DYNAMIC_EXECUTION]: The skill assembles shell scripts at runtime and executes them within a temporary Cloud Run Job environment.
- Evidence in
scripts/deploy.py: Thebuild_seed_yamlfunction generates configuration which is then passed into a shell heredoc for execution viaexecute_operator_job_command. - Evidence in
scripts/deploy.py: Thecreate_temporary_operator_jobfunction configures a Cloud Run job to execute arbitrary commands passed as arguments. - [INDIRECT_PROMPT_INJECTION]: The skill has a high vulnerability surface for indirect injection as it ingests entire repositories while maintaining extensive system and cloud capabilities.
- Ingestion points: Repository content cloned from user-supplied URLs as specified in
SKILL.md. - Boundary markers: None; the instructions do not include safeguards against malicious instructions within the cloned repository.
- Capability inventory: Shell command execution in
scripts/_common.py, network access to third-party APIs inscripts/deploy.py, IAM policy management, and Cloud SQL/Secret Manager operations inscripts/deploy.py. - Sanitization: No validation or sanitization is performed on the scripts or configuration files within the cloned repository before they are executed.
Recommendations
- AI detected serious security threats
Audit Metadata