google-agents-cli-publish

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [Data Processing Surface]: The skill involves reading local project files, such as deployment_metadata.json, uv.lock, and toolspec.json, to automate registration and check for environment compatibility. While standard for development workflows, these files represent a point where external data is ingested into the agent's context.
  • Ingestion points: deployment_metadata.json, toolspec.json, uv.lock (referenced in SKILL.md).
  • Boundary markers: None explicitly defined within the instructions.
  • Capability inventory: Shell command execution via agents-cli and gcloud, network communication with Google Cloud APIs.
  • Sanitization: The skill assumes the integrity of the local development environment and project files.
  • [Tool Integration]: The skill utilizes the agents-cli and gcloud command-line interfaces to perform management tasks. These operations are aligned with the skill's intended purpose of managing agent lifecycles on Google Cloud infrastructure.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 07:35 AM
Security Audit — agent-trust-hub — google-agents-cli-publish