skills/jswortz/my-skills/gcp-diagram/Gen Agent Trust Hub

gcp-diagram

Pass

Audited by Gen Agent Trust Hub on May 6, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches official GCP icon assets from trusted Google domains (services.google.com) to provide accurate and compliant diagram components.\n- [COMMAND_EXECUTION]: Provides a local Python script (scripts/overlay_icons.py) that uses the Pillow library to post-process diagrams by overlaying official product icons. This script performs legitimate image manipulation within the skill's scope.\n- [REMOTE_CODE_EXECUTION]: Employs the official google-genai library to communicate with Vertex AI models for the purpose of image generation. This is a standard and expected integration for this skill's use case.\n- [DATA_EXFILTRATION]: Sends user-provided architecture descriptions to Google's Vertex AI platform. This data flow is necessary for the skill's core functionality and targets a well-known, trusted service.\n- [PROMPT_INJECTION]: Includes a surface for indirect prompt injection where user input is interpolated into image generation templates.\n
  • Ingestion points: User-supplied architecture descriptions are used to populate templates in SKILL.md.\n
  • Boundary markers: Absent from templates in references/templates.md.\n
  • Capability inventory: Limited to image generation via Vertex AI and local file processing with scripts/overlay_icons.py.\n
  • Sanitization: No validation is applied to user input, but the risk is mitigated by the non-executable output format and mandatory verification steps.
Audit Metadata
Risk Level
SAFE
Analyzed
May 6, 2026, 02:09 PM
Security Audit — agent-trust-hub — gcp-diagram