skills/google/skills/bigquery-basics/Gen Agent Trust Hub

bigquery-basics

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [External Library Management]: The skill provides instructions for installing official BigQuery client libraries using standard package managers like pip and npm. These are verified packages from the service provider and are a routine part of the development workflow.
  • [Command Attribution Tracking]: The skill instructs the agent to include specific metadata in gcloud and curl headers. This is a common practice for service providers to track skill usage for analytics and does not involve the collection or exfiltration of sensitive user data.
  • [Data Ingestion and Querying]: The skill includes patterns for loading data from external sources (such as Cloud Storage) and executing SQL queries. While these operations involve processing external content, the skill incorporates references to security best practices like IAM roles, encryption, and VPC Service Controls to manage access and protect data.
  • [Remote MCP Tooling]: The instructions mention using a remote Model Context Protocol (MCP) server for automated management. The server-side tools implement safety constraints, such as limiting SQL execution to read-only SELECT statements, to maintain a secure operating environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 07:52 PM
Security Audit — agent-trust-hub — bigquery-basics