google-cloud-filestore-log-troubleshooting
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- Command Execution: The skill operates by executing
gcloudCLI commands via the Pythonsubprocessmodule to gather diagnostic information and apply fixes. scripts/quick_diagnose.pyusessubprocess.runto call commands likegcloud filestore instances describeandgcloud logging read.- The implementation uses argument lists rather than shell strings, reducing the risk of command injection within the scripts themselves.
- Indirect Prompt Injection Surface: The skill processes external data from Cloud Audit logs and Kubernetes (GKE) CSI driver logs, which are potentially influenced by actors in the cloud environment.
- Ingestion points: Untrusted log data enters the agent context through the
get_recent_audit_logsandget_client_csi_errorsfunctions inscripts/quick_diagnose.py. - Boundary markers: The skill does not explicitly wrap ingested log content in delimiters meant to signal the agent to ignore embedded instructions.
- Capability inventory: The skill possesses the ability to create VPC firewall rules and update Filestore instance configurations via the
gcloudCLI. - Sanitization: The skill extracts information from JSON or text logs for reporting without specific sanitization of natural language content inside those fields.
- Interactive Remediation Gate: To mitigate the risk of unauthorized modifications, the skill enforces a mandatory confirmation checkpoint before any destructive or corrective actions occur.
- Instructions in
SKILL.mdexplicitly require the agent to ask for user confirmation before calling therun_commandtool for remediation. - The
scripts/quick_diagnose.pyscript requires a specific--apply-fixflag to execute modification commands, preventing accidental execution during the diagnostic phase.
Audit Metadata