gcp-secret-manager
Pass
Audited by Gen Agent Trust Hub on Jun 28, 2026
Risk Level: SAFECREDENTIALS_UNSAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides standard documentation for a well-known service (Google Cloud Secret Manager) using official tools and libraries. No malicious behavior or suspicious obfuscation was detected.\n- [CREDENTIALS_UNSAFE]: The documentation contains illustrative example passwords (e.g., 'S3cur3P@ssw0rd!') within bash commands. These are clearly marked as placeholders and do not represent a security risk.\n- [PROMPT_INJECTION]: The skill identifies a surface for indirect prompt injection as it facilitates the ingestion of secret data from external GCP APIs. This risk is inherent to tools that process external configuration or secrets. Ingestion points: gcloud CLI and SDK access methods. Capability inventory: GCP network communication and command execution via gcloud. Sanitization: Not applicable to the provided example snippets.
Audit Metadata