agent-platform-alert-configuration

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFE
Full Analysis
  • Command Execution: The skill utilizes subprocess.run in scripts/gather_agent_info.py to interact with Google Cloud CLI tools like gcloud and bq. This is used to discover project settings and agent details. The implementation follows security best practices by passing arguments as a sequence (list) rather than using shell strings, which effectively mitigates common command injection risks.
  • Authentication and Network Operations: Several scripts, such as scripts/list_log_scope_table_names.py and scripts/list_trace_scope_table_names.py, perform authenticated requests to Google Cloud APIs. These scripts use standard Google Application Default Credentials (ADC) to obtain OAuth2 tokens and communicate only with official googleapis.com endpoints to retrieve resource metadata.
  • Resource Management Safety: The SKILL.md file defines clear safety tiers. It explicitly instructs the AI agent to stop and request user approval before executing 'Tier B' actions, such as provisioning Vertex AI Online Monitors or creating BigQuery datasets, which involve billing costs and resource creation. This demonstrates a robust approach to user authorization and cost management.
  • Configuration Validation: The skill includes a dedicated linting utility (scripts/lint_syntax.py and scripts/config_utils.py) that performs syntax checks on generated PromQL queries and Terraform HCL blocks. This helps ensure the reliability and correctness of the output configuration before deployment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 08:08 PM
Security Audit — agent-trust-hub — agent-platform-alert-configuration