cspm-gcp-cis-benchmark

Pass

Audited by Gen Agent Trust Hub on Apr 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements automated security checks using official Google Cloud SDKs and follows the principle of least privilege by requiring only read-only permissions (roles/viewer and roles/iam.securityReviewer).
  • [DATA_EXPOSURE]: The skill accesses GCP metadata (IAM policies, bucket configurations, firewall rules) for assessment purposes. This behavior is consistent with the stated purpose and is restricted to read-only operations via Application Default Credentials (ADC).
  • [COMMAND_EXECUTION]: No usage of subprocess, os.system, or other command execution utilities was found. All operations are performed via Python client libraries.
  • [REMOTE_CODE_EXECUTION]: No patterns of remote script execution or dynamic code evaluation were detected.
  • [EXTERNAL_DOWNLOADS]: Dependencies are restricted to standard, well-known GCP client libraries available on official package registries.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 20, 2026, 01:17 AM
Security Audit — agent-trust-hub — cspm-gcp-cis-benchmark