google-cloud-storage-basics

Pass

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • Official Package Installation: The skill references standard installation procedures for client libraries (google-cloud-storage for Python and @google-cloud/storage for Node.js) and system utilities. These are fetched from official package registries.
  • Verified External Binaries: For Model Context Protocol (MCP) functionality, the skill directs users to download a binary from a vendor-controlled storage endpoint. This is a common practice for distributing specialized tooling.
  • Administrative Command Execution: The instructions for installing system-level adapters involve the use of sudo to add repository keys and install software. These are standard administrative tasks for environment setup and are used appropriately within the context of the skill's instructions.
  • Data Attribution and Metrics: The skill suggests including attribution tags in command-line and API requests. This is a standard mechanism for usage tracking and does not involve the collection or transmission of sensitive user data.
  • Security Best Practices: The documentation explicitly encourages the use of fine-grained access control, uniform bucket-level access, and public access prevention. It also provides specific warnings regarding the irreversible nature of certain data protection features, such as locking retention policies.
  • Indirect Prompt Injection Surface: As a storage management skill, the tools can read content from external objects. The documentation proactively addresses this potential risk by recommending the use of screening services to mitigate injection attempts.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 22, 2026, 11:34 PM
Security Audit — agent-trust-hub — google-cloud-storage-basics