gcp-serverless-appdev

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides architecture documentation, implementation patterns, and project templates for GCP serverless services such as Cloud Run, Firestore, and Cloud Tasks.
  • [SAFE]: Secret management practices recommended in the skill are secure, utilizing dotenvx for encrypted environment variables and Google Cloud Secret Manager for runtime secrets, while explicitly prohibiting the use of long-lived service account keys.
  • [SAFE]: Dependencies, container images, and external tools referenced (e.g., FastAPI, Next.js, Ruff, Sentry) are standard, official, or originate from well-known and trusted organizations.
  • [SAFE]: Deployment and CI/CD instructions rely on secure authentication via Workload Identity Federation (OIDC) between GitHub Actions and Google Cloud, minimizing the risk of credential leakage.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 05:25 PM
Security Audit — agent-trust-hub — gcp-serverless-appdev