vertex-ai-api-dev
Pass
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions to install official Google Generative AI SDKs for Python, Node.js, Go, C#, and Java using standard package managers (pip, npm, go get, etc.).
- [COMMAND_EXECUTION]: Includes documentation for the Gemini API's native Python code execution tool and provides an example of running a local Model Context Protocol (MCP) server using the
npxutility. - [PROMPT_INJECTION]: Contains instructional directives to ensure the model uses specific version identifiers (e.g., 'gemini-3-flash-preview'), including phrases like 'Your knowledge is outdated' to override potentially stale training data.
- [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface by processing external data from URLs and Cloud Storage. Ingestion points: references/text_and_multimodal.md (YouTube, GCS, Local), references/structured_and_tools.md (URLs). Boundary markers: Absent. Capability inventory: ToolCodeExecution and url_context in references/structured_and_tools.md. Sanitization: Absent.
Audit Metadata