agent-platform-model-registry

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute various gcloud ai models commands to manage resources in the Google Cloud Platform Model Registry. This includes operations like list, describe, upload, update, and delete.
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to command injection via untrusted data processed at runtime. User-provided values for variables such as $MODEL_ID, $VERSION_ID, $PROJECT_ID, and search queries are interpolated directly into shell commands.
  • Ingestion points: User-provided inputs for variables $MODEL_ID, $VERSION_ID, $PROJECT_ID, $LOCATION_ID, and the search query in gcloud ai model-garden models list (SKILL.md).
  • Boundary markers: None present to delimit user input from shell command structures.
  • Capability inventory: The skill has the ability to write to, update, and delete resources in a Google Cloud project via the gcloud CLI.
  • Sanitization: There are no instructions for the agent to sanitize or validate user-supplied variables before execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:40 AM
Security Audit — agent-trust-hub — agent-platform-model-registry