Back to skill

Security audit

Google Cloud Platform

Security checks for vulnerabilities and agentic risk

Overview

This is a broad Google Cloud command-reference skill with real cloud-admin risks, but the behavior is visible, purpose-aligned, and not deceptive.

Install only if you intend to let an agent help with broad Google Cloud administration. Use least-privilege GCP accounts, confirm the project and region before running commands, avoid public access flags unless intended, do not type production secrets or database passwords inline, and prefer pinned or verified installer methods where possible.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:16
Finding

Unverified Google Cloud CLI Download and Installer Execution

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:32
Finding

Unpinned Global Firebase CLI Dependency Installation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:331
Finding

Secret Values Embedded Directly in Shell Commands

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:469
Finding

Cloud SQL Password Exposed as a Command-Line Argument

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 336)May include surrounding context.

--project PROJECT_ID

Or from file

gcloud secrets create SECRET_NAME --data-file=./secret.txt --project PROJECT_ID

text

### Access Secrets

Credential Access

High
Category
Privilege Escalation
Confidence
83% confidence
Finding

The 'Access Secrets' section gives direct commands to read secret values (gcloud secrets versions access ...), which is inherently sensitive capability. In a broadly scoped infrastructure skill, such instructions increase the risk of credential disclosure if an agent is over-authorized or if users invoke the commands without explicit need-to-know controls.

Content

Scanner excerpt · SKILL.md (reported line 339)May include surrounding context.

gcloud secrets create SECRET_NAME --data-file=./secret.txt --project PROJECT_ID

text

### Access Secrets

```bash
# Get latest version

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description at L003 defines a fairly specific operational scope, but the file later documents creating, accessing, rotating, and destroying secrets in Secret Manager. Secret lifecycle administration is materially different from the stated resource-management categories and is not mentioned in the manifest description.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

L003 describes a skill for GCP resource management focused on VMs, Cloud Run, Firebase Hosting, Cloud Storage, project management, deployment, monitoring, logs, and SSH. The later Artifact Registry section covers repository creation, Docker credential setup, image build/push, and image deletion, which is a separate service area not represented in the manifest description.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest description does not mention databases, yet the file documents creating SQL instances, databases, users, backups, restores, and connectivity. Database administration is a significant additional capability beyond the services explicitly named in the manifest.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill provides deployment and remote access commands that can materially change exposed services or connect to production systems, yet it lacks safety guidance about authorization, environment targeting, public exposure, rollback, or blast radius. In an agent context, omission of such guardrails increases the chance of accidental deployment, service exposure, or disruptive actions.

Content

No source excerpt is available for this finding.

Cloud Storage Exfiltration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is uploaded to cloud storage (S3 / GCS / Azure Blob). This may be a legitimate backup or exfiltration to an external bucket. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 230)May include surrounding context.

md
gsutil ls gs://BUCKET_NAME/

# Copy file
gsutil cp LOCAL_FILE gs://BUCKET_NAME/path/
gsutil cp gs://BUCKET_NAME/path/file LOCAL_PATH

# Sync directory

Cloud Storage Exfiltration

Medium
Category
Data Exfiltration
Confidence
71% confidence
Finding

gsutil cp gs://BUCKET_NAME/path/file LOCAL_PATH explicitly documents downloading cloud-hosted data to a local path, which can facilitate data exfiltration if used on sensitive buckets by an overprivileged agent or user. In a cloud-admin skill, this is contextually legitimate, but the absence of warnings or controls around sensitive data handling makes it a genuine misuse-enabling capability.

Content

Scanner excerpt · SKILL.md (reported line 231)May include surrounding context.

md
# Copy file
gsutil cp LOCAL_FILE gs://BUCKET_NAME/path/
gsutil cp gs://BUCKET_NAME/path/file LOCAL_PATH

# Sync directory
gsutil -m rsync -r LOCAL_DIR gs://BUCKET_NAME/path/

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

Billing-account inspection and budget creation at L270-L303 go beyond the concrete service list in the manifest and introduce financial governance actions. While related to cloud administration, this is distinct enough from the stated scope that users could underestimate the skill's reach.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.