gcloud

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill includes instructions to download and install the Google Cloud SDK using the official installation script: curl https://sdk.cloud.google.com | bash. This targets a well-known service provided by Google.
  • [COMMAND_EXECUTION]: The skill facilitates extensive command-line operations via the gcloud, bq, and gsutil utilities. These include resource creation, deletion, authentication management, and service configuration across Google Cloud Platform.
  • [INDIRECT_PROMPT_INJECTION]: The skill contains instructions for reading external data that could be attacker-controlled.
  • Ingestion points: Data is ingested through commands like gcloud logging read, gcloud run services logs read, gcloud storage cp, and gcloud secrets versions access (referenced in SKILL.md and references/SERVICES.md).
  • Boundary markers: No explicit delimiters or boundary instructions are provided for handling the output of these commands.
  • Capability inventory: The skill has the capability to execute shell commands, write to the file system (e.g., gcloud iam service-accounts keys create key.json), and perform network operations via the Google Cloud APIs.
  • Sanitization: There is no evidence of specific sanitization or filtering of the content retrieved from external Google Cloud services before it is presented to the agent context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 03:08 PM
Security Audit — agent-trust-hub — gcloud