cloud-sql-basics
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- Infrastructure Management via Command Execution: The skill provides a detailed reference for using
gcloudcommands to provision and manage Cloud SQL instances, databases, and users. These patterns are consistent with the skill's primary purpose of database administration. - Official Library Dependencies: The documentation references the installation of official Google Cloud connectors and client libraries using standard package managers (pip, npm, Maven, and Go). These resources are well-known, vendor-provided tools designed to facilitate secure database connections.
- Security and Identity Management Guidance: A significant portion of the skill is dedicated to security best practices. It explicitly documents the risks associated with broad IAM permissions, such as the
setIamPolicycapability, and recommends using IAM database authentication to avoid the use of static credentials. - Indirect Prompt Injection Surface: The Model Context Protocol (MCP) reference in
references/mcp-usage.mddescribes tools likeexecute_sqlthat allow an agent to interact with a database. - Ingestion points: Untrusted data could theoretically enter the agent context through SQL query results or be passed into the
execute_sqltool parameters. - Boundary markers: The documentation suggests using a restricted
readonlytoolset endpoint to limit the agent's capabilities. - Capability inventory: Tools include instance management, user creation, and SQL execution.
- Sanitization: The skill recommends following the principle of least privilege and using IAM roles to restrict what the agent can perform at the resource level.
Audit Metadata