gcp-cloud-run
Pass
Audited by Gen Agent Trust Hub on Apr 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements and promotes industry-standard security practices for cloud deployments, such as using non-root users in Dockerfiles (
USER node), employing Secret Manager for sensitive data, and utilizing distroless images to minimize attack surfaces.\n- [SAFE]: Includes comprehensive validation checks that instruct the agent to identify and warn against security risks like hardcoded credentials, root execution, and unsafe file operations in user code.\n- [COMMAND_EXECUTION]: Provides standardgcloudCLI commands for deploying and managing GCP resources, which is the primary and intended purpose of the skill.\n- [EXTERNAL_DOWNLOADS]: References official Google Cloud container images (gcr.io/cloud-builders/*,gcr.io/google.com/cloudsdktool/*) and standard package registries (NPM, PyPI) which are recognized as trusted and well-known services.
Audit Metadata