gcp-agent-registry

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The helper script scripts/registry.py invokes the gcloud CLI tool to obtain transient authentication tokens.\n
  • Evidence: The adc_token function uses subprocess.run(["gcloud", "auth", "application-default", "print-access-token"], ...) to fetch the ADC token.\n
  • Context: This is a secure and standard practice for GCP authentication in development environments, ensuring that credentials are not hardcoded or stored insecurely within the skill.\n- [EXTERNAL_DOWNLOADS]: The skill performs network operations to interact with Google Cloud's Agent Registry service.\n
  • Evidence: The script makes REST API calls to https://agentregistry.googleapis.com/v1alpha for managing skills and revisions.\n
  • Context: These requests target a well-known service from a trusted organization (Google) and are necessary for the skill's primary function.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes data from the GCP Agent Registry, which represents a potential surface for indirect prompt injection from externally stored skill content.\n
  • Ingestion points: The skill retrieves skill metadata (JSON) and revision content (ZIP) from the agentregistry.googleapis.com API through the list, get, and search commands.\n
  • Boundary markers: The skill instructions include an explicit "Issue gate" in references/issues.md to guide the agent in handling API inconsistencies, but do not define specific delimiters for separating ingested content from agent instructions.\n
  • Capability inventory: The skill possesses file system access (read/write for ZIP processing) and network communication capabilities with Google Cloud APIs.\n
  • Sanitization: Ingested data is handled using standard library functions for JSON and base64; no additional sanitization or filtering of the natural language content within skill descriptions is performed before it is analyzed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 03:48 PM
Security Audit — agent-trust-hub — gcp-agent-registry