gcpctx-cicd
Pass
Audited by Gen Agent Trust Hub on Aug 1, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions to install the
gcpctxutility globally via npm (npm install -g gcpctx). This package is a core component of the skill's functionality and is maintained by the skill author. - [COMMAND_EXECUTION]: The skill includes shell command examples for authenticating with GCP (
gcloud auth activate-service-account), managing project contexts (gcpctx init,gcpctx use), and performing deployments (gcloud run deploy). These commands are standard for CI/CD automation. - [CREDENTIALS_UNSAFE]: The skill demonstrates how to manage GCP Service Account keys by decoding them into temporary files (e.g.,
/tmp/key.json) for authentication. It appropriately includes best practice recommendations for cleaning up these sensitive files after use. - [PROMPT_INJECTION]: The skill allows for the interpolation of environment variables and CI/CD secrets into command-line arguments. While this creates a surface for indirect prompt injection, the provided examples use standard shell quoting and are intended for deployment automation rather than direct LLM processing.
Audit Metadata