Cloud Penetration Testing

Fail

Audited by Gen Agent Trust Hub on Feb 16, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • Remote Code Execution (LOW): The skill uses a piped bash execution pattern to install the Google Cloud SDK.
  • Evidence: Automated scans identified the command curl https://sdk.cloud.google.com | bash.
  • Trust Evaluation: The domain sdk.cloud.google.com belongs to Google, which is a trusted organization. Under the [TRUST-SCOPE-RULE], this finding is downgraded to LOW severity as the source is within the defined trusted scope.
Recommendations
  • CRITICAL: Downloads and executes remote code from untrusted source(s): https://sdk.cloud.google.com - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Feb 16, 2026, 12:32 PM