gcp-expert

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides legitimate documentation and code examples for GCP. It includes a restricted set of allowed tools in the frontmatter, limiting command execution to the gcloud CLI. No signs of credential exfiltration, obfuscation, or persistence were found.
  • [INDIRECT_PROMPT_INJECTION]: The skill documents how to process data from BigQuery, Firestore, and Pub/Sub, which introduces an ingestion point for external data. 1. Ingestion points: Results from BigQuery queries in SKILL.md, Firestore document streams in SKILL.md, and Pub/Sub message payloads in SKILL.md. 2. Boundary markers: The snippets do not include explicit delimiter markers or warnings for the agent to ignore instructions within the data. 3. Capability inventory: The skill utilizes Read, Write, Edit, and gcloud Bash tools across the GCP management context. 4. Sanitization: Examples focus on connectivity and do not include data validation or sanitization logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 06:00 AM
Security Audit — agent-trust-hub — gcp-expert