gcp-serverless-appdev
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides architecture documentation, implementation patterns, and project templates for GCP serverless services such as Cloud Run, Firestore, and Cloud Tasks.
- [SAFE]: Secret management practices recommended in the skill are secure, utilizing dotenvx for encrypted environment variables and Google Cloud Secret Manager for runtime secrets, while explicitly prohibiting the use of long-lived service account keys.
- [SAFE]: Dependencies, container images, and external tools referenced (e.g., FastAPI, Next.js, Ruff, Sentry) are standard, official, or originate from well-known and trusted organizations.
- [SAFE]: Deployment and CI/CD instructions rely on secure authentication via Workload Identity Federation (OIDC) between GitHub Actions and Google Cloud, minimizing the risk of credential leakage.
Audit Metadata