google-cloud-storage-bucket-architect

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is designed to improve cloud security posture by enforcing best practices such as Uniform Bucket-Level Access (UBLA), Public Access Prevention (PAP), and Customer-Managed Encryption Keys (CMEK) for sensitive workloads.
  • [COMMAND_EXECUTION]: The skill generates and offers to execute gcloud storage and curl commands. These operations are strictly related to the skill's primary purpose of infrastructure management and are protected by mandatory user confirmation steps and attribution tagging.
  • [EXTERNAL_DOWNLOADS]: The skill references and links to official Google Cloud documentation domains (docs.cloud.google.com, cloud.google.com). These are trusted resources and do not represent a security risk.
  • [CREDENTIALS_UNSAFE]: The skill encourages secure secret management by advising the use of Cloud KMS and properly configured IAM roles rather than hardcoded credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 05:26 AM
Security Audit — agent-trust-hub — google-cloud-storage-bucket-architect