gcp-essentials
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill promotes secure-by-default configurations for Google Cloud Platform, explicitly advising against the use of service account JSON keys, primitive roles like Owner/Editor for workloads, and public IP addresses for database instances.
- [SAFE]: It includes a local verification script (
scripts/verify.sh) designed to perform static analysis on gcloud command blocks to detect common security misconfigurations, such as missing bucket security flags or over-privileged Cloud Run deployments. - [SAFE]: The instructions recommend using well-known and official tools for CI/CD, specifically the
google-github-actions/authaction for keyless authentication via Workload Identity Federation. - [SAFE]: No patterns associated with prompt injection, data exfiltration, obfuscation, or unauthorized remote code execution were found.
Audit Metadata