event-driven-architecture-on-google-cloud

Fail

Audited by Gen Agent Trust Hub on Jun 25, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSSAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: A reference to the known phishing/malicious domain malicious-site.com was found in the reference documentation.
  • Evidence: In references/how-to-build-ai-agents-with-google-managed-mcp-servers.md, the URL http://malicious-site.com is used in a string within a tutorial section.
  • Context: The domain is specifically used to demonstrate how Google Cloud Model Armor can detect and block malicious URIs. While intended as a 'bad example' for educational purposes, the inclusion of a valid phishing URL string in the skill context can be flagged by automated filters and presents a low risk of accidental navigation or inclusion in agent-generated responses.
  • [SAFE]: The skill is comprised entirely of documentation and does not include any executable components.
  • Evidence: No scripts (.sh, .py, .js), installation files, or automated configurations were found across the 17 files.
  • Evidence: Technical examples and code snippets provided in the guides follow secure coding practices, such as recommending the use of environment variables for secrets management.
  • Evidence: Automated AV scans flagged references/how-to-build-ai-agents-with-google-managed-mcp-servers.md as suspicious for 'HttpRequest-inf'. Manual review indicates this is a false positive triggered by the presence of HTTP request examples and JSON policy snippets used to illustrate security configurations.
Recommendations
  • CRITICAL: 1 infected file(s) detected - DO NOT USE
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Jun 25, 2026, 01:46 PM
Security Audit — agent-trust-hub — event-driven-architecture-on-google-cloud