wendy-gcp-deployment

Pass

Audited by Gen Agent Trust Hub on Aug 7, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill documents secure infrastructure-as-code practices, specifically mandating the use of GitHub OIDC for authentication to avoid hardcoded credentials or long-lived service account keys.
  • [SAFE]: The instructions enforce the Principle of Least Privilege (PoLP) by requiring the creation of custom IAM roles with specific, minimized permissions rather than using broad, predefined admin roles.
  • [PROMPT_INJECTION]: The skill utilizes a requirements interview process to gather user input for infrastructure design. While this serves as an ingestion surface for indirect prompt injection, the instructions include specific validation rules and mandatory human review for all generated commands and designs, effectively mitigating the risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 7, 2026, 10:08 PM
Security Audit — agent-trust-hub — wendy-gcp-deployment