gcloud-cli-health-check
Fail
Audited by Gen Agent Trust Hub on Apr 28, 2026
Risk Level: HIGHCREDENTIALS_UNSAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill uses
gcloud auth print-access-tokenandgcloud auth application-default print-access-tokento retrieve active Google Cloud bearer tokens. These tokens provide temporary full access to cloud resources if intercepted. - [COMMAND_EXECUTION]: The skill mandates the use of
mcp__Desktop_Commander__start_processto execute shell commands directly on the user's host machine (macOS), which operates outside of standard agent safety sandboxes. - [PROMPT_INJECTION]: The instructions explicitly direct the agent to disregard the built-in sandboxed Bash tool, characterizing its security restrictions and network blocks as failures to be bypassed by using more privileged tools.
- [DATA_EXFILTRATION]: The skill systematically aggregates sensitive cloud infrastructure metadata, including IAM roles, service account lists, and billing configurations, into a consolidated report file stored in the workspace.
Recommendations
- AI detected serious security threats
Audit Metadata