workload-manager-basics

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • Command Execution: The skill documentation provides examples of using gcloud and curl for authentication, service enablement, and interacting with the REST API. These are standard management operations for Google Cloud resources.
  • External Package Installation: The instructions include the installation of the official google-cloud-workloadmanager Python package and the Go client library. These are vendor-provided libraries used for programmatic access to the service.
  • Indirect Prompt Injection Surface: There is a potential security consideration when the agent processes and displays evaluation results, such as violation messages, which are retrieved from scanned cloud resources. If these messages contain content specifically crafted to influence agent behavior, it could lead to misinterpretation.
  • Ingestion points: Validation results and violation messages are ingested via client.list_execution_results in references/client-library-usage.md and through REST API calls in references/rest-usage.md.
  • Boundary markers: Explicit boundary markers or instructions to ignore embedded commands are not present in the provided code snippets.
  • Capability inventory: The skill primarily demonstrates listing and printing results, but agents utilizing these results may have access to other shell or file system capabilities.
  • Sanitization: There is no explicit sanitization or filtering of the retrieved violation messages in the example code provided.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 05:39 AM
Security Audit — agent-trust-hub — workload-manager-basics