google-cloud-storage-bucket-architect

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided workload descriptions and requirements to generate architectural plans and shell commands. Although it employs secure defaults and mandates user confirmation, the absence of input boundary markers or sanitization creates an attack surface for indirect prompt injection. 1. Ingestion points: User requirements and use-case descriptions in Phase 2. 2. Boundary markers: None. 3. Capability inventory: Execution of gcloud CLI and curl targeting Google APIs; access to authentication tokens. 4. Sanitization: None.
  • [COMMAND_EXECUTION]: The skill generates and executes commands using gcloud and curl to verify project-level security policies (e.g., TLS 1.2, HTTPS enforcement) and provision storage resources. All mutating operations require explicit user approval.
  • [DYNAMIC_EXECUTION]: The skill generates code and configuration blocks for various environments including Terraform, Python, Go, Java, and C++ based on user requirements and predefined logic templates.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 01:35 PM
Security Audit — agent-trust-hub — google-cloud-storage-bucket-architect