google-agents-cli-adk-code
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- Markdown Table Structure (False Positive): The automated security scan identified a potential remote code execution pattern (
curl ... | Python). However, manual verification confirms this is a false positive result of markdown table parsing. The pipe character|in theSKILL.mdfile is a table separator between the 'Reference' and 'Language' columns, not a shell pipe operator. - Trusted Documentation References: The skill includes links to
adk.dev, the official documentation site for the Agent Development Kit. These references are used to provide the agent and user with authoritative product information and do not represent a security risk. - Official Development Ecosystem: The skill utilizes official Google packages such as
google-adkand follows recommended development workflows. It includes clear instructions for secure secret management, such as the use of environment variables rather than hardcoded credentials. - External Dependencies: The skill mentions standard tools and libraries required for ADK development, including the
google-agents-cliand Node.js-based MCP components. These are well-known and expected dependencies for the intended use case.
Audit Metadata