bigquery-auth

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFEPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute various gcloud CLI commands to manage project configurations, authenticate accounts, and switch between project profiles.
  • [CREDENTIALS_UNSAFE]: The skill provides instructions for using service account JSON keys stored at ~/.gcp/{SA_KEY_FILE}.json and utilizes gcloud auth application-default print-access-token which outputs sensitive access tokens to the console.
  • [PROMPT_INJECTION]: Exhibits an indirect prompt injection surface as it interpolates user-supplied data (GCP Project IDs and Profile Names) directly into shell commands and Python code.
  • Ingestion points: User-provided strings for {PROJECT_ID} and {PROFILE_NAME} in SKILL.md.
  • Boundary markers: Absent; values are interpolated directly into command strings.
  • Capability inventory: Subprocess execution via gcloud commands and Python script execution via the google-cloud-bigquery library.
  • Sanitization: No explicit sanitization or validation of the project ID or profile name format is mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 05:58 AM
Security Audit — agent-trust-hub — bigquery-auth