event-driven-architecture-on-google-cloud
Fail
Audited by Gen Agent Trust Hub on Jun 25, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSSAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: A reference to the known phishing/malicious domain
malicious-site.comwas found in the reference documentation. - Evidence: In
references/how-to-build-ai-agents-with-google-managed-mcp-servers.md, the URLhttp://malicious-site.comis used in a string within a tutorial section. - Context: The domain is specifically used to demonstrate how Google Cloud Model Armor can detect and block malicious URIs. While intended as a 'bad example' for educational purposes, the inclusion of a valid phishing URL string in the skill context can be flagged by automated filters and presents a low risk of accidental navigation or inclusion in agent-generated responses.
- [SAFE]: The skill is comprised entirely of documentation and does not include any executable components.
- Evidence: No scripts (.sh, .py, .js), installation files, or automated configurations were found across the 17 files.
- Evidence: Technical examples and code snippets provided in the guides follow secure coding practices, such as recommending the use of environment variables for secrets management.
- Evidence: Automated AV scans flagged
references/how-to-build-ai-agents-with-google-managed-mcp-servers.mdas suspicious for 'HttpRequest-inf'. Manual review indicates this is a false positive triggered by the presence of HTTP request examples and JSON policy snippets used to illustrate security configurations.
Recommendations
- CRITICAL: 1 infected file(s) detected - DO NOT USE
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata