google-agents-cli-adk-code

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • Markdown Table Structure (False Positive): The automated security scan identified a potential remote code execution pattern (curl ... | Python). However, manual verification confirms this is a false positive result of markdown table parsing. The pipe character | in the SKILL.md file is a table separator between the 'Reference' and 'Language' columns, not a shell pipe operator.
  • Trusted Documentation References: The skill includes links to adk.dev, the official documentation site for the Agent Development Kit. These references are used to provide the agent and user with authoritative product information and do not represent a security risk.
  • Official Development Ecosystem: The skill utilizes official Google packages such as google-adk and follows recommended development workflows. It includes clear instructions for secure secret management, such as the use of environment variables rather than hardcoded credentials.
  • External Dependencies: The skill mentions standard tools and libraries required for ADK development, including the google-agents-cli and Node.js-based MCP components. These are well-known and expected dependencies for the intended use case.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 07:35 AM
Security Audit — agent-trust-hub — google-agents-cli-adk-code