skills/uriber/gcpctx/gcpctx-cicd/Gen Agent Trust Hub

gcpctx-cicd

Pass

Audited by Gen Agent Trust Hub on Aug 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to install the gcpctx utility globally via npm (npm install -g gcpctx). This package is a core component of the skill's functionality and is maintained by the skill author.
  • [COMMAND_EXECUTION]: The skill includes shell command examples for authenticating with GCP (gcloud auth activate-service-account), managing project contexts (gcpctx init, gcpctx use), and performing deployments (gcloud run deploy). These commands are standard for CI/CD automation.
  • [CREDENTIALS_UNSAFE]: The skill demonstrates how to manage GCP Service Account keys by decoding them into temporary files (e.g., /tmp/key.json) for authentication. It appropriately includes best practice recommendations for cleaning up these sensitive files after use.
  • [PROMPT_INJECTION]: The skill allows for the interpolation of environment variables and CI/CD secrets into command-line arguments. While this creates a surface for indirect prompt injection, the provided examples use standard shell quoting and are intended for deployment automation rather than direct LLM processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 1, 2026, 12:25 PM
Security Audit — agent-trust-hub — gcpctx-cicd