Cloud Penetration Testing
Fail
Audited by Gen Agent Trust Hub on Feb 16, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
- Remote Code Execution (LOW): The skill uses a piped bash execution pattern to install the Google Cloud SDK.
- Evidence: Automated scans identified the command
curl https://sdk.cloud.google.com | bash. - Trust Evaluation: The domain
sdk.cloud.google.combelongs to Google, which is a trusted organization. Under the [TRUST-SCOPE-RULE], this finding is downgraded to LOW severity as the source is within the defined trusted scope.
Recommendations
- CRITICAL: Downloads and executes remote code from untrusted source(s): https://sdk.cloud.google.com - DO NOT USE
Audit Metadata