workload-manager-basics
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- Command Execution: The skill documentation provides examples of using
gcloudandcurlfor authentication, service enablement, and interacting with the REST API. These are standard management operations for Google Cloud resources. - External Package Installation: The instructions include the installation of the official
google-cloud-workloadmanagerPython package and the Go client library. These are vendor-provided libraries used for programmatic access to the service. - Indirect Prompt Injection Surface: There is a potential security consideration when the agent processes and displays evaluation results, such as violation messages, which are retrieved from scanned cloud resources. If these messages contain content specifically crafted to influence agent behavior, it could lead to misinterpretation.
- Ingestion points: Validation results and violation messages are ingested via
client.list_execution_resultsinreferences/client-library-usage.mdand through REST API calls inreferences/rest-usage.md. - Boundary markers: Explicit boundary markers or instructions to ignore embedded commands are not present in the provided code snippets.
- Capability inventory: The skill primarily demonstrates listing and printing results, but agents utilizing these results may have access to other shell or file system capabilities.
- Sanitization: There is no explicit sanitization or filtering of the retrieved violation messages in the example code provided.
Audit Metadata