gcp

Pass

Audited by Gen Agent Trust Hub on Jul 29, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses gcloud and bq CLI tools to interact with Google Cloud services, which is its primary purpose. The associated bash scripts implement performance optimizations using parallel background jobs and efficient formatting flags to handle large datasets safely.\n- [PROMPT_INJECTION]: The skill includes 'CRITICAL' instructions aimed at preventing 'hallucinations' and ensuring mathematical accuracy during billing analysis. These rules act as technical safeguards for data processing rather than attempts to override agent security guardrails.\n- [DATA_EXFILTRATION]: No evidence of unauthorized data transfer was found. The skill's access to sensitive billing data is confined to official Google Cloud APIs through standard, authenticated CLI tools.\n- [PROMPT_INJECTION]: The skill processes external data from BigQuery billing tables (Ingestion Point: scripts/get_billing_gcp.sh). While it lacks explicit boundary markers for data content, the risk is managed by mandatory SQL casting and schema-aware interpretation rules. The skill's capabilities are limited to standard bq query and gcloud calls (Capability Inventory), and while direct sanitization is absent in the helper scripts, the instructions enforce strict logical filtering (Sanitization: project.id filtering).
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 29, 2026, 06:01 AM
Security Audit — agent-trust-hub — gcp