google-agents-cli-publish
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- Command Execution: The skill instructs the agent to execute shell commands using
agents-cliandgcloud. These commands are used to manage agent registrations, list resources, and update service metadata within Google Cloud. While these are intended functionalities for the tool, they involve interaction with the underlying system. - External Package Installation: The skill references the installation of
google-agents-cliusing theuvtool. This package appears to be a resource provided by the vendor (Google) for managing agent deployments. Following standard security practices, users should ensure they are using official packages from trusted registries. - Indirect Prompt Injection Surface: The skill includes mechanisms to ingest data from local files like
deployment_metadata.jsonanduv.lock, as well as fetching content from external URLs provided via the--agent-card-urlflag. - Ingestion points:
deployment_metadata.json,uv.lock, and remote agent card JSON files. - Boundary markers: The skill instructions do not explicitly define delimiters or specific sanitization steps for the data processed from these external sources.
- Capability inventory: The tool has the capability to execute shell commands via
agents-cliandgcloudbased on the configuration data it processes. - Sanitization: There is no specific mention of input validation or sanitization for the external agent cards or metadata files within the skill instructions.
Audit Metadata