retail-virtual-tryon
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEPRIVILEGE_ESCALATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- Privilege Management: The
scripts/setup_tryon.pyscript manages Google Cloud project permissions, including granting roles likeroles/aiplatform.userandroles/storage.objectAdminto the default compute service account. These high-privilege operations are necessary for the application to function on Google Cloud and are performed using documentedgcloudcommands during the setup phase. - Shell Command Execution: The skill uses subprocesses in scripts such as
setup.py,bootstrap.sh, andsetup_tryon.pyto manage environment dependencies withpipand provision cloud services via thegcloudCLI. These executions are part of the intended installation and configuration workflow. - External Service Integration: The skill integrates with official Google Cloud services, specifically Gemini and Veo for image and video generation, and Google Cloud Storage for asset management. It utilizes established, versioned client libraries from the vendor.
- Data Handling Practices: The application processes user-uploaded photos and product descriptions. It includes a privacy-focused feature in
scripts/setup_tryon.pythat configures a 24-hour auto-deletion lifecycle rule for user-uploaded photos in Cloud Storage. Product descriptions provided via the agent are interpolated into model prompts inscripts/tryon_processor.pyfor task execution, which is a common pattern for generative AI agents.
Audit Metadata