google-cloud-data-engineering-hub
Warn
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill facilitates the download of a large external repository from a third-party GitHub account (https://github.com/vishal-bulbule/google-cloud-data-engineering-hub.git). This repository contains more than 50 projects including scripts and configuration files that are not part of the skill's own audited code.
- [REMOTE_CODE_EXECUTION]: The instructions direct the agent to install third-party dependencies via
pip install -r requirements.txtwithin the cloned repository and execute the main pipeline code (python main.py). This pattern executes unverified code downloaded from a remote source at runtime. - [COMMAND_EXECUTION]: The skill encourages the execution of local shell scripts (
deploy.sh) to automate GCP resource creation. These scripts are granted executable permissions (chmod +x) and run with project-level credentials, which could lead to unauthorized resource modification if the source repository were compromised. - [INDIRECT_PROMPT_INJECTION]: The skill establishes several surfaces for ingesting untrusted data that the agent then processes:
- Ingestion points:
bigquery.Client.load_table_from_file,beam.io.ReadFromTextfor CSV/Text files,pubsub_v1.SubscriberClientfor message streams, andGenerativeModel.generate_contentfor PDFs and images. - Boundary markers: No explicit boundary markers or instructions to ignore embedded commands are present in the provided Python snippets.
- Capability inventory: The skill possesses significant capabilities including writing to BigQuery and Cloud Storage, publishing to Pub/Sub, and triggering Vertex AI generation.
- Sanitization: The provided examples lack sanitization or validation of the external content before it is processed or passed to downstream AI models.
Audit Metadata