gcp-agent-registry
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The helper script
scripts/registry.pyinvokes thegcloudCLI tool to obtain transient authentication tokens.\n - Evidence: The
adc_tokenfunction usessubprocess.run(["gcloud", "auth", "application-default", "print-access-token"], ...)to fetch the ADC token.\n - Context: This is a secure and standard practice for GCP authentication in development environments, ensuring that credentials are not hardcoded or stored insecurely within the skill.\n- [EXTERNAL_DOWNLOADS]: The skill performs network operations to interact with Google Cloud's Agent Registry service.\n
- Evidence: The script makes REST API calls to
https://agentregistry.googleapis.com/v1alphafor managing skills and revisions.\n - Context: These requests target a well-known service from a trusted organization (Google) and are necessary for the skill's primary function.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes data from the GCP Agent Registry, which represents a potential surface for indirect prompt injection from externally stored skill content.\n
- Ingestion points: The skill retrieves skill metadata (JSON) and revision content (ZIP) from the
agentregistry.googleapis.comAPI through thelist,get, andsearchcommands.\n - Boundary markers: The skill instructions include an explicit "Issue gate" in
references/issues.mdto guide the agent in handling API inconsistencies, but do not define specific delimiters for separating ingested content from agent instructions.\n - Capability inventory: The skill possesses file system access (read/write for ZIP processing) and network communication capabilities with Google Cloud APIs.\n
- Sanitization: Ingested data is handled using standard library functions for JSON and base64; no additional sanitization or filtering of the natural language content within skill descriptions is performed before it is analyzed by the agent.
Audit Metadata