google-cloud-filestore-log-troubleshooting

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • Command Execution: The skill operates by executing gcloud CLI commands via the Python subprocess module to gather diagnostic information and apply fixes.
  • scripts/quick_diagnose.py uses subprocess.run to call commands like gcloud filestore instances describe and gcloud logging read.
  • The implementation uses argument lists rather than shell strings, reducing the risk of command injection within the scripts themselves.
  • Indirect Prompt Injection Surface: The skill processes external data from Cloud Audit logs and Kubernetes (GKE) CSI driver logs, which are potentially influenced by actors in the cloud environment.
  • Ingestion points: Untrusted log data enters the agent context through the get_recent_audit_logs and get_client_csi_errors functions in scripts/quick_diagnose.py.
  • Boundary markers: The skill does not explicitly wrap ingested log content in delimiters meant to signal the agent to ignore embedded instructions.
  • Capability inventory: The skill possesses the ability to create VPC firewall rules and update Filestore instance configurations via the gcloud CLI.
  • Sanitization: The skill extracts information from JSON or text logs for reporting without specific sanitization of natural language content inside those fields.
  • Interactive Remediation Gate: To mitigate the risk of unauthorized modifications, the skill enforces a mandatory confirmation checkpoint before any destructive or corrective actions occur.
  • Instructions in SKILL.md explicitly require the agent to ask for user confirmation before calling the run_command tool for remediation.
  • The scripts/quick_diagnose.py script requires a specific --apply-fix flag to execute modification commands, preventing accidental execution during the diagnostic phase.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 06:24 AM
Security Audit — agent-trust-hub — google-cloud-filestore-log-troubleshooting