google-cloud-recipe-foundation-builder

Pass

Audited by Gen Agent Trust Hub on Jul 9, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [IAM Role Remediation Strategy]: The skill includes instructions to automatically grant required administrative roles (such as Organization Administrator and Billing Administrator) to the deployment identity if permission errors occur. This 'lazy recovery' approach is designed to ensure the successful setup of a foundational environment while requiring the user to have the initial authority to perform these grants.
  • [Organization-Level Configuration]: The skill executes commands to create resource folders, link billing accounts, and enforce organization-wide security policies. These are high-privilege operations necessary for the skill's stated purpose of building a secure enterprise landing zone.
  • [Standard Cloud Management Tools]: The workflow relies exclusively on the official gcloud CLI and interacts with standard Google Cloud APIs, following the vendor's recommended architecture for centralized logging and monitoring.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 9, 2026, 04:29 AM
Security Audit — agent-trust-hub — google-cloud-recipe-foundation-builder