bigquery-auth
Pass
Audited by Gen Agent Trust Hub on May 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFEPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute various
gcloudCLI commands to manage project configurations, authenticate accounts, and switch between project profiles. - [CREDENTIALS_UNSAFE]: The skill provides instructions for using service account JSON keys stored at
~/.gcp/{SA_KEY_FILE}.jsonand utilizesgcloud auth application-default print-access-tokenwhich outputs sensitive access tokens to the console. - [PROMPT_INJECTION]: Exhibits an indirect prompt injection surface as it interpolates user-supplied data (GCP Project IDs and Profile Names) directly into shell commands and Python code.
- Ingestion points: User-provided strings for
{PROJECT_ID}and{PROFILE_NAME}inSKILL.md. - Boundary markers: Absent; values are interpolated directly into command strings.
- Capability inventory: Subprocess execution via
gcloudcommands and Python script execution via thegoogle-cloud-bigquerylibrary. - Sanitization: No explicit sanitization or validation of the project ID or profile name format is mentioned.
Audit Metadata