google-agents-cli-scaffold

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • External Tool Installation: The skill requires the installation of the google-agents-cli tool via the uv package manager. This is a vendor-provided utility necessary for the skill's primary purpose of project scaffolding and infrastructure management.
  • Command Execution: The skill involves executing agents-cli commands to create, enhance, and upgrade projects. These operations are used to manage local project environments and infrastructure files as requested by the user.
  • Indirect Prompt Injection Surface: The skill ingests user requirements (Phase 0) to guide the scaffolding process.
  • Ingestion points: User requirement clarification and architecture choices.
  • Boundary markers: The skill lacks explicit prompt delimiters but requires mandatory user clarification before execution.
  • Capability inventory: The skill utilizes subprocess calls to the agents-cli tool to perform file writes and environment configuration.
  • Sanitization: The process relies on standard CLI parameter handling within the agents-cli tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 07:35 AM
Security Audit — agent-trust-hub — google-agents-cli-scaffold