google-cloud-recipe-onboarding

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill uses official Google Cloud CLI (gcloud) commands to perform onboarding tasks such as authentication, project creation, and billing linkage.
  • [SAFE]: All external URLs and repository references target official Google domains and organizations, providing trusted resources for the skill's functionality.
  • [SAFE]: The skill implements a mandatory 'Structured Confirmation & Consent Gate' in Section 3, ensuring that resource mutations and billing changes only occur after explicit user affirmation.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from gcloud CLI JSON outputs and user-supplied project details. Boundary markers are present via a mandatory structured confirmation markdown table and consent query. Capabilities include project creation and billing linkage commands. While explicit sanitization is absent, the risk is mitigated by the manual confirmation gate.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:41 AM
Security Audit — agent-trust-hub — google-cloud-recipe-onboarding