helm-chart-builder
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses Python scripts (
scripts/chart_analyzer.pyandscripts/values_validator.py) and standard Helm CLI commands (helm lint,helm template,helm dependency update) for static analysis and validation. These are standard development tools for the stated purpose of Helm chart creation and auditing. - [REMOTE_CODE_EXECUTION]: The skill includes installation instructions involving
git clonefrom the author's GitHub repository and an optional conversion script (scripts/convert.sh). These are documented, user-initiated setup steps common for AI agent skills and do not involve silent or untrusted execution. - [DATA_EXPOSURE]: The skill provides explicit guidance and automated checks to prevent secret exposure, specifically warning against hardcoding credentials in
values.yamland providing remediation steps (Category 2 mitigation). - [PRIVILEGE_ESCALATION]: The skill provides security auditing guidelines that specifically recommend against privilege escalation, advising users to set
allowPrivilegeEscalation: falseandrunAsNonRoot: truein Kubernetes manifests.
Audit Metadata