managing-gcp-policy-intelligence

Pass

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill defines several Bash scripts that execute gcloud commands to list IAM insights, recommendations, and perform policy troubleshooting. These commands are used to discover current resource states and identify security improvements.
  • [PROMPT_INJECTION]: The skill ingests data from GCP, such as IAM insight descriptions and recommendation details. This represents an indirect prompt injection surface where a malicious actor with control over GCP resource metadata could attempt to influence the agent's behavior through the gathered data.
  • Ingestion points: SKILL.md (via CLI output from gcloud recommender and gcloud asset).
  • Boundary markers: The scripts use formatting flags (e.g., --format='table(...)') and output limits (e.g., head -15) to structure the data.
  • Capability inventory: The skill is primarily focused on read-only discovery and analysis (list, analyze, troubleshoot) across all included scripts.
  • Sanitization: No explicit sanitization or filtering of the retrieved data is performed before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 23, 2026, 11:53 AM
Security Audit — agent-trust-hub — managing-gcp-policy-intelligence