gemini-enterprise
Pass
Audited by Gen Agent Trust Hub on May 6, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill facilitates interaction with official Google Cloud Discovery Engine and Model Armor APIs. All operations are consistent with administrative and search-based workflows for enterprise AI applications.
- [PROMPT_INJECTION]: The skill identifies an indirect prompt injection surface when the agent processes data from external sources like Google Cloud Storage or public web crawls. This risk is effectively addressed through the documented implementation of Model Armor content safety filters.
- Ingestion points: Documents from GCS buckets and content from crawled websites (SKILL.md, references/provisioning.md).
- Boundary markers: The skill relies on grounding and standard LLM processing rather than explicit markers.
- Capability inventory: The agent can search document stores, perform conversational reasoning, and delegate to sub-agents (scripts/stream_assist_client.py, SKILL.md).
- Sanitization: Explicitly configures Model Armor to filter for prompt injection, jailbreaks, and PII in both user input and model output (references/api_reference.md, references/provisioning.md).
Audit Metadata