skills/google/skills/gke-backup-dr/Gen Agent Trust Hub

gke-backup-dr

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • Command Execution Platform Tools: The skill provides instructions for the agent to execute gcloud CLI commands. These commands are used to modify GKE cluster settings and manage backup resources, which represent sensitive administrative actions on cloud infrastructure.
  • Indirect Prompt Injection Surface: The skill uses command templates that incorporate user-provided inputs (such as {cluster_name} and {project_id}). This presents a potential surface where unvalidated user input could be used to manipulate the behavior of generated commands.
  • Ingestion points: User-supplied resource identifiers, project IDs, and configuration strings within the gcloud command blocks.
  • Boundary markers: No specific delimiters or boundary markers are defined for the interpolated user data.
  • Capability inventory: The skill utilizes gcloud to perform cluster updates, backup plan creation, and restore execution, which includes resource deletion capabilities depending on the conflict policy.
  • Sanitization: The instructions do not specify a process for sanitizing or escaping user-provided parameters before they are executed in the shell.
  • Sensitive Data Handling: The skill includes functionality to capture Kubernetes Secrets and persistent volume data in backups. While necessary for disaster recovery, these operations involve the movement of sensitive credentials and application data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 05:39 AM
Security Audit — agent-trust-hub — gke-backup-dr