google-agents-cli-deploy

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • Vendor Tool Dependency: The skill requires the installation of google-agents-cli using uv. This is a deployment tool provided by the vendor (Google) to facilitate the packaging and deployment of agents.
  • Infrastructure Command Execution: The instructions involve the use of standard cloud management tools such as gcloud, kubectl, and terraform to provision resources and manage deployments on Google Cloud Platform.
  • Secure Secret Management: The skill explicitly recommends and provides instructions for using Google Cloud Secret Manager to store and access API keys and other sensitive credentials, avoiding the risk of hardcoded secrets.
  • Authenticated CI/CD Integration: The CI/CD pipeline setup utilizes Workload Identity Federation (WIF). This is a security best practice that allows external identities (like GitHub Actions) to access Google Cloud resources without the need for long-lived, high-risk service account keys.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 07:35 AM
Security Audit — agent-trust-hub — google-agents-cli-deploy