google-cloud-solution-n-tier-serverless-web-app
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- Command Execution: The skill provides a structured sequence of Google Cloud CLI (
gcloud) and Terraform commands. These are intended to be executed by the user to provision and manage infrastructure. The commands follow a 'bottom-up' deployment strategy to ensure correct resource dependencies and security wiring. - Dynamic Script Generation: To assist with post-deployment verification, the skill generates custom Python scripts using standard libraries. These scripts are designed to validate that the security boundaries, such as WAF protection and ingress restrictions, are correctly implemented.
- Indirect Prompt Injection Surface: The skill acts as an assistant that generates code based on user-provided requirements. This capability represents a potential attack surface where input could influence the generated infrastructure code. However, the skill explicitly incorporates non-negotiable architectural rules and grounding references to mitigate this risk and ensure adherence to security standards.
Audit Metadata