google-agents-cli-workflow
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- Command Execution & Package Installation: The skill utilizes uv and agents-cli to manage the development environment. These commands facilitate tool installation and execution from vendor-controlled sources, which is a standard part of the ADK workflow.
- Extension System: The skill documents a manifest-based extension system that allows users to define custom scripts for project commands. This design incorporates a trust model where the tool prompts for authorization when adding non-shorthand extensions, maintaining user oversight over execution.
- Indirect Prompt Injection Surface: The agent is instructed to read project-specific files like .agents-cli-spec.md and source code. While this creates a channel for external data to influence the agent, the skill mitigates risk through a multi-phase workflow requiring explicit human design approval and deployment confirmation.
- Safety and Preservation Guidelines: The instructions include operational principles that restrict the agent's autonomy, such as preventing unrequested model changes and requiring surgical code modification. These guidelines are designed to maintain project stability and follow security best practices for automated coding tasks.
Audit Metadata