cloudrun-development
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes third-party application source code and container images, which constitutes a surface for indirect prompt injection if the ingested content contains malicious instructions.
- Ingestion points: The skill reads from local source paths (
targetPath) and remote container registries (imageUrl). - Boundary markers: While it refers to security protocols for data protection, there are no specific prompt delimiters defined to isolate ingested code from agent instructions.
- Capability inventory: The skill utilizes
manageCloudRunfor service deployment, configuration updates, traffic management, and resource deletion. - Sanitization: The instructions explicitly mandate the use of the
sensitive-runtime-data-protection.mdprotocol to prevent credential leakage. - [EXTERNAL_DOWNLOADS]: The skill facilitates the download and deployment of container images from well-known registries like Docker Hub and the vendor's internal Container Registry (CCR).
- [COMMAND_EXECUTION]: The
manageCloudRuntool is used to execute administrative actions on the CloudBase platform, including building source code, deploying versions, and managing canary releases. - [CREDENTIALS_UNSAFE]: The documentation mentions handling sensitive connection strings (e.g.,
DATABASE_URL) and platform credentials (x-cloudbase-context). However, it provides defensive guidance against echoing these values in responses or logs, representing a safe practice for credential management.
Audit Metadata