google-cloud-recipe-foundation-builder
Fail
Audited by Snyk on Jul 9, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). The recipe contains an explicit "lazy remediation" flow that automatically runs gcloud add-iam-policy-binding / billing accounts add-iam-policy-binding to grant entire high-privilege administrative role groups to the active identity on permission failures, which is an intentional privilege-escalation/backdoor pattern that can be abused to gain broad organization-level control.
Issues (1)
E006
CRITICALMalicious code pattern detected in skill scripts.
Audit Metadata