adk-engineer
Pass
Audited by Gen Agent Trust Hub on Aug 11, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: Fetches the google-adk package from the official registry during project initialization using pip install in the init script.\n- [DYNAMIC_EXECUTION]: The scripts/validate_agent.py utility uses importlib.util to dynamically load and execute local agent code to verify compliance with best practices.\n- [INDIRECT_PROMPT_INJECTION]: The skill provides templates for agents that ingest and process external data. This attack surface is mitigated by security guidance in references/adk-best-practices.md.\n
- Ingestion points: User query inputs in template agent.py files.\n
- Boundary markers: Documentation recommends explicit validation tools and safety instructions.\n
- Capability inventory: Templates include tools for database searching, data fetching, and analysis.\n
- Sanitization: Documentation includes code examples for implementing input validation logic.
Audit Metadata