gcp-cloud-run
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides code templates that ingest untrusted data from HTTP requests and event triggers, creating a surface where malicious instructions in external data could influence the agent during development or testing cycles.
- Ingestion points:
req.bodyandreq.queryinSKILL.md(HTTP Function),cloudEvent.datainSKILL.md(Pub/Sub and Storage Functions). - Boundary markers: Absent. The provided templates do not demonstrate the use of delimiters or 'ignore embedded instructions' warnings for external data.
- Capability inventory: The skill utilizes
gcloudCLI tools and Node.js for networking and file operations across various patterns. - Sanitization: Absent. The templates show direct usage of input (e.g.,
req.query.name) or standardJSON.parsewithout validation logic. - [COMMAND_EXECUTION]: The skill includes instructions for deploying infrastructure and building containers using the Google Cloud CLI and Cloud Build.
- The skill provides templates using
gcloud run deploy,gcloud functions deploy, andgcr.io/cloud-builders/dockerto manage serverless resources. - Deployment configurations in
SKILL.mdinclude the--allow-unauthenticatedflag, which enables public access to the deployed services.
Audit Metadata