NYC

google-adk-python

Pass

Audited by Gen Agent Trust Hub on Feb 16, 2026

Risk Level: LOWEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS] (LOW): The skill provides installation instructions for the 'google-adk' package and its development version from a trusted GitHub repository.
  • Evidence: 'pip install google-adk' and 'pip install git+https://github.com/google/adk-python.git@main' in SKILL.md.
  • Trust Status: The 'google' organization is a Trusted External Source, downgrading this finding to LOW per [TRUST-SCOPE-RULE].
  • [COMMAND_EXECUTION] (INFO): The documentation includes patterns for building agents with code execution and search capabilities.
  • Evidence: Mentions of 'google_search' and 'code_execution' tools in the Implementation Patterns section of SKILL.md.
  • Analysis: These are legitimate features of the library being documented for developer use and do not represent a vulnerability in the skill's own logic.
Audit Metadata
Risk Level
LOW
Analyzed
Feb 16, 2026, 03:57 AM