cloudrun-development

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides comprehensive guidance on the secure management of CloudBase Run environments, emphasizing the use of the manageAppAuth tool to generate environment-specific API keys instead of reusing local client credentials.\n- [SAFE]: The instructions include specific warnings against common security pitfalls, such as echoing sensitive environment variables (e.g., CLOUDBASE_APIKEY) or temporary platform credentials (x-cloudbase-context) in HTTP responses.\n- [SAFE]: Deployment workflows for container images and source code utilize platform-native tools (manageCloudRun) and follow industry-standard practices, including the use of VPC configurations to secure database connectivity.\n- [SAFE]: The troubleshooting documentation provides a structured approach to diagnosing deployment issues through official runtime logs (getProcessLog), explicitly advising against arbitrary changes to security-sensitive parameters like readiness probe delays without evidence.\n- [INDIRECT_PROMPT_INJECTION]: The skill manages a deployment attack surface where user-provided code or images are processed. This is mitigated by clear boundary markers (initialization checks), capability inventory (restricted to manageCloudRun), and sanitization (credential decision gates).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 09:21 AM
Security Audit — agent-trust-hub — cloudrun-development