make-python-recipe-deployable
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [Command Execution]: The skill uses
subprocess.runto interact with external tools likedockeranduv. These calls are implemented using list-based arguments rather than shell strings, which effectively mitigates the risk of command injection. This is used for legitimate verification and dependency management tasks. - [Safe YAML Parsing]: While static analysis flagged the use of
yaml.load(), the implementation inscripts/make_deployable.pyexplicitly usesruamel.yamlwith thetyp='safe'parameter. This is a secure configuration equivalent toSafeLoader, preventing the execution of arbitrary code during the parsing of configuration files. - [Docker Usage and Allowlisting]: The skill leverages Docker to build and run containerized versions of recipes for verification. The documentation (
SKILL.md) correctly identifies that building arbitrary Dockerfiles can be a security consideration and implements arun_allowlistpolicy to restrict the execution of containers that were not directly generated by the skill's own templates. - [External Tooling]: The skill incorporates well-known development tools such as
uvandruff. It fetches theuvbinary within the generated Dockerfile from a standard registry (pip), which is a common and accepted practice for creating reproducible build environments. - [Trusted Vendor Context]: The skill and its associated templates are authored by Google and target Google Cloud services. All external resource references point to official Google domains and repositories, consistent with the tool's intended purpose as a GCP development utility.
Audit Metadata