boost-factory-gcp-api
Pass
Audited by Gen Agent Trust Hub on Jun 24, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is purely documentation-oriented, defining configuration parameters for GCP services (BigQuery, Firestore, PubSub).
- [SAFE]: The skill explicitly includes a security best practice warning under the 'Red flags' section, advising users not to hardcode service-account JSON in repositories and suggesting the use of Vault or workload identity instead.
- [SAFE]: The 'allowed-tools' section limits shell access to specific development tools (go, golangci-lint, git), which is appropriate for a development-focused skill.
- [SAFE]: No malicious patterns such as prompt injection, obfuscation, or unauthorized data exfiltration were detected.
Audit Metadata