skills/google/skills/gke-inference/Gen Agent Trust Hub

gke-inference

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFE
Full Analysis
  • Official Tool Integration: The skill utilizes official google-managed tools such as gcloud and kubectl. These operations are consistent with standard cloud administration and do not involve untrusted third-party binaries or scripts.
  • Secure Secret Management: The skill explicitly advises users to store sensitive credentials (like Hugging Face tokens) using Kubernetes Secrets rather than hardcoding them into manifests or environment variables, which aligns with security best practices.
  • Kubernetes Resource Management: The skill uses standard Kubernetes resources (ComputeClass, HorizontalPodAutoscaler) and commands (apply_k8s_manifest, get_k8s_logs) to manage the lifecycle of inference workloads. These capabilities are within the expected scope for a GKE-focused deployment skill.
  • No Remote Execution Detected: The skill does not perform any remote script downloads, piped execution (e.g., curl to bash), or access to non-vendor external repositories. All discovery and deployment steps are handled through the authenticated gcloud environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 05:39 AM
Security Audit — agent-trust-hub — gke-inference