T08 · Insecure Dependencies
- Location
SKILL.md:16- Finding
Unverified Google Cloud CLI Download and Installer Execution
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a broad Google Cloud command-reference skill with real cloud-admin risks, but the behavior is visible, purpose-aligned, and not deceptive.
Install only if you intend to let an agent help with broad Google Cloud administration. Use least-privilege GCP accounts, confirm the project and region before running commands, avoid public access flags unless intended, do not type production secrets or database passwords inline, and prefer pinned or verified installer methods where possible.
SKILL.md:16Unverified Google Cloud CLI Download and Installer Execution
SKILL.md:32Unpinned Global Firebase CLI Dependency Installation
SKILL.md:331Secret Values Embedded Directly in Shell Commands
SKILL.md:469Cloud SQL Password Exposed as a Command-Line Argument
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
--project PROJECT_ID
gcloud secrets create SECRET_NAME --data-file=./secret.txt --project PROJECT_ID
### Access Secrets
The 'Access Secrets' section gives direct commands to read secret values (gcloud secrets versions access ...), which is inherently sensitive capability. In a broadly scoped infrastructure skill, such instructions increase the risk of credential disclosure if an agent is over-authorized or if users invoke the commands without explicit need-to-know controls.
gcloud secrets create SECRET_NAME --data-file=./secret.txt --project PROJECT_ID
### Access Secrets
```bash
# Get latest version
The manifest description at L003 defines a fairly specific operational scope, but the file later documents creating, accessing, rotating, and destroying secrets in Secret Manager. Secret lifecycle administration is materially different from the stated resource-management categories and is not mentioned in the manifest description.
L003 describes a skill for GCP resource management focused on VMs, Cloud Run, Firebase Hosting, Cloud Storage, project management, deployment, monitoring, logs, and SSH. The later Artifact Registry section covers repository creation, Docker credential setup, image build/push, and image deletion, which is a separate service area not represented in the manifest description.
The manifest description does not mention databases, yet the file documents creating SQL instances, databases, users, backups, restores, and connectivity. Database administration is a significant additional capability beyond the services explicitly named in the manifest.
The skill provides deployment and remote access commands that can materially change exposed services or connect to production systems, yet it lacks safety guidance about authorization, environment targeting, public exposure, rollback, or blast radius. In an agent context, omission of such guardrails increases the chance of accidental deployment, service exposure, or disruptive actions.
Data is uploaded to cloud storage (S3 / GCS / Azure Blob). This may be a legitimate backup or exfiltration to an external bucket. Manual review is recommended.
gsutil ls gs://BUCKET_NAME/
# Copy file
gsutil cp LOCAL_FILE gs://BUCKET_NAME/path/
gsutil cp gs://BUCKET_NAME/path/file LOCAL_PATH
# Sync directory
gsutil cp gs://BUCKET_NAME/path/file LOCAL_PATH explicitly documents downloading cloud-hosted data to a local path, which can facilitate data exfiltration if used on sensitive buckets by an overprivileged agent or user. In a cloud-admin skill, this is contextually legitimate, but the absence of warnings or controls around sensitive data handling makes it a genuine misuse-enabling capability.
# Copy file
gsutil cp LOCAL_FILE gs://BUCKET_NAME/path/
gsutil cp gs://BUCKET_NAME/path/file LOCAL_PATH
# Sync directory
gsutil -m rsync -r LOCAL_DIR gs://BUCKET_NAME/path/
Billing-account inspection and budget creation at L270-L303 go beyond the concrete service list in the manifest and introduce financial governance actions. While related to cloud administration, this is distinct enough from the stated scope that users could underestimate the skill's reach.
No suspicious patterns detected.