cloudrun-development

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes third-party application source code and container images, which constitutes a surface for indirect prompt injection if the ingested content contains malicious instructions.
  • Ingestion points: The skill reads from local source paths (targetPath) and remote container registries (imageUrl).
  • Boundary markers: While it refers to security protocols for data protection, there are no specific prompt delimiters defined to isolate ingested code from agent instructions.
  • Capability inventory: The skill utilizes manageCloudRun for service deployment, configuration updates, traffic management, and resource deletion.
  • Sanitization: The instructions explicitly mandate the use of the sensitive-runtime-data-protection.md protocol to prevent credential leakage.
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the download and deployment of container images from well-known registries like Docker Hub and the vendor's internal Container Registry (CCR).
  • [COMMAND_EXECUTION]: The manageCloudRun tool is used to execute administrative actions on the CloudBase platform, including building source code, deploying versions, and managing canary releases.
  • [CREDENTIALS_UNSAFE]: The documentation mentions handling sensitive connection strings (e.g., DATABASE_URL) and platform credentials (x-cloudbase-context). However, it provides defensive guidance against echoing these values in responses or logs, representing a safe practice for credential management.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 09:35 AM
Security Audit — agent-trust-hub — cloudrun-development