gcp-deploy-guardian

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes untrusted content from project configuration files that could influence agent behavior.
  • Ingestion points: The skill reads contents from Dockerfile, cloudbuild.yaml, nginx.conf, and vite.config.ts during the audit process.
  • Boundary markers: No explicit delimiters or instructions are used to separate the content of external files from the agent's instructions.
  • Capability inventory: The skill has significant capabilities, including executing shell commands via Bash (using docker, gcloud, and kubectl tools) and making network requests via WebFetch.
  • Sanitization: Data from external files is analyzed via direct reading and grep without specific sanitization to filter out potential prompt injection attempts.
  • [COMMAND_EXECUTION]: The skill utilizes Bash to run validation scripts and standard deployment tools. It performs architecture checks, audits build arguments, and verifies deployment status using gcloud, kubectl, and docker commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 05:08 PM
Security Audit — agent-trust-hub — gcp-deploy-guardian