agent-platform-alert-configuration
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFE
Full Analysis
- Command Execution: The skill utilizes
subprocess.runinscripts/gather_agent_info.pyto interact with Google Cloud CLI tools likegcloudandbq. This is used to discover project settings and agent details. The implementation follows security best practices by passing arguments as a sequence (list) rather than using shell strings, which effectively mitigates common command injection risks. - Authentication and Network Operations: Several scripts, such as
scripts/list_log_scope_table_names.pyandscripts/list_trace_scope_table_names.py, perform authenticated requests to Google Cloud APIs. These scripts use standard Google Application Default Credentials (ADC) to obtain OAuth2 tokens and communicate only with officialgoogleapis.comendpoints to retrieve resource metadata. - Resource Management Safety: The
SKILL.mdfile defines clear safety tiers. It explicitly instructs the AI agent to stop and request user approval before executing 'Tier B' actions, such as provisioning Vertex AI Online Monitors or creating BigQuery datasets, which involve billing costs and resource creation. This demonstrates a robust approach to user authorization and cost management. - Configuration Validation: The skill includes a dedicated linting utility (
scripts/lint_syntax.pyandscripts/config_utils.py) that performs syntax checks on generated PromQL queries and Terraform HCL blocks. This helps ensure the reliability and correctness of the output configuration before deployment.
Audit Metadata