gcp-review
Pass
Audited by Gen Agent Trust Hub on Jul 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or behaviors were detected. The skill is designed for security posture assessment.
- [SAFE]: The skill processes untrusted infrastructure-as-code files. It includes a dedicated 'Prompt Injection Safety Notice' instructing the agent to treat configuration content as data and to ignore any directives embedded within those files. This effectively mitigates the risk of indirect prompt injection.
- [SAFE]: Tool access is limited to read-only operations (Read, Grep, Glob). There are no capabilities for network communication, system modification, or code execution.
Audit Metadata