Security audit
Google Pub/Sub
Security checks for vulnerabilities and agentic risk
Overview
This plugin is coherent and purpose-aligned, but it uses Google credentials to consume Pub/Sub messages, so it should be configured with least-privilege access to only the intended subscriptions.
Before installing, confirm the subscription is intended for automated consumption, use a dedicated least-privilege Pub/Sub subscriber credential, avoid broad ADC credentials where possible, keep the default Google endpoint unless you trust the override, and remember that pulled messages will be acknowledged and exposed to the agent.
Static analysis
No suspicious patterns detected.
