gcp-toolkit
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: No patterns of behavior override, DAN-style instructions, or safety filter bypasses were identified. The instructions maintain a professional, advisory tone for architectural guidance.
- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill promotes high-security standards by mandating Workload Identity and customer-managed encryption keys (CMEK). It explicitly identifies the use of long-lived JSON service account keys and primitive IAM roles as red-flag security risks.
- [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: No remote script downloads or piped command executions were detected. The skill references legitimate, industry-standard security tools (Checkov, TFSec, Trivy) to be used locally for scanning infrastructure-as-code.
- [INDIRECT_PROMPT_INJECTION]: The skill correctly identifies that processing external requirements presents an attack surface and mitigates this by enforcing automated security scans and mandatory human approval gates before any infrastructure mutations are applied.
- [OBFUSCATION]: Analysis of the skill body and metadata found no hidden characters, Base64-encoded commands, or other obfuscation techniques designed to conceal malicious intent.
Audit Metadata