gcp-batch-inline-script-text

Inline Batch runnable scripts can hard-code credentials or sensitive shell content.

gcpcritical service: gcp:batch emits ContainsCredential

Where it sits

locationbatch.projects.locations.jobs.get.taskGroups[].taskSpec.runnables[].script.text
location kindbootstrap_script
data kindssource_code_secret credential password api_key private_key
emits edgeContainsCredential
serviceBatch (gcp:batch)

Collection recipe

access moderead_api
operationbatch.projects.locations.jobs.get
response pathtaskGroups[].taskSpec.runnables[].script.text
encodingstring
params{"name": "\u003cresource-name\u003e"}

Required permissions

batch.jobs.get

References

move · open · esc close