Back to plugin

Security audit

Google Pub/Sub

Security checks for vulnerabilities and agentic risk

Overview

This plugin is coherent and purpose-aligned, but it uses Google credentials to consume Pub/Sub messages, so it should be configured with least-privilege access to only the intended subscriptions.

Before installing, confirm the subscription is intended for automated consumption, use a dedicated least-privilege Pub/Sub subscriber credential, avoid broad ADC credentials where possible, keep the default Google endpoint unless you trust the override, and remember that pulled messages will be acknowledged and exposed to the agent.

Static analysis

No suspicious patterns detected.