gcp-essentials

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill promotes secure-by-default configurations for Google Cloud Platform, explicitly advising against the use of service account JSON keys, primitive roles like Owner/Editor for workloads, and public IP addresses for database instances.
  • [SAFE]: It includes a local verification script (scripts/verify.sh) designed to perform static analysis on gcloud command blocks to detect common security misconfigurations, such as missing bucket security flags or over-privileged Cloud Run deployments.
  • [SAFE]: The instructions recommend using well-known and official tools for CI/CD, specifically the google-github-actions/auth action for keyless authentication via Workload Identity Federation.
  • [SAFE]: No patterns associated with prompt injection, data exfiltration, obfuscation, or unauthorized remote code execution were found.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 09:36 PM
Security Audit — agent-trust-hub — gcp-essentials