gcloud-cli-health-check

Fail

Audited by Gen Agent Trust Hub on Apr 28, 2026

Risk Level: HIGHCREDENTIALS_UNSAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill uses gcloud auth print-access-token and gcloud auth application-default print-access-token to retrieve active Google Cloud bearer tokens. These tokens provide temporary full access to cloud resources if intercepted.
  • [COMMAND_EXECUTION]: The skill mandates the use of mcp__Desktop_Commander__start_process to execute shell commands directly on the user's host machine (macOS), which operates outside of standard agent safety sandboxes.
  • [PROMPT_INJECTION]: The instructions explicitly direct the agent to disregard the built-in sandboxed Bash tool, characterizing its security restrictions and network blocks as failures to be bypassed by using more privileged tools.
  • [DATA_EXFILTRATION]: The skill systematically aggregates sensitive cloud infrastructure metadata, including IAM roles, service account lists, and billing configurations, into a consolidated report file stored in the workspace.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Apr 28, 2026, 01:39 PM
Security Audit — agent-trust-hub — gcloud-cli-health-check