gcp-expert
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides legitimate documentation and code examples for GCP. It includes a restricted set of allowed tools in the frontmatter, limiting command execution to the gcloud CLI. No signs of credential exfiltration, obfuscation, or persistence were found.
- [INDIRECT_PROMPT_INJECTION]: The skill documents how to process data from BigQuery, Firestore, and Pub/Sub, which introduces an ingestion point for external data. 1. Ingestion points: Results from BigQuery queries in SKILL.md, Firestore document streams in SKILL.md, and Pub/Sub message payloads in SKILL.md. 2. Boundary markers: The snippets do not include explicit delimiter markers or warnings for the agent to ignore instructions within the data. 3. Capability inventory: The skill utilizes Read, Write, Edit, and gcloud Bash tools across the GCP management context. 4. Sanitization: Examples focus on connectivity and do not include data validation or sanitization logic.
Audit Metadata