kubernetes-troubleshooting

Warn

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains instructions that explicitly discourage the agent from seeking user confirmation before performing actions. In Workflow Step 4, it instructs: "do not stop with a natural-language next step. Call kubernetes_fix_access... Do not end with soft phrasing like 'If you want me to proceed...'." This pattern of concealment reduces user oversight for potentially dangerous operations.- [COMMAND_EXECUTION]: The skill relies on executing powerful administrative commands via kubectl, Helm, and Ansible. It describes a 'kubernetes_fix_access' tool that uses 'sudo install' to modify system file permissions and ownership, representing a privilege escalation path managed by the agent instructions.- [DATA_EXFILTRATION]: The skill is designed to access sensitive configuration files, specifically '/etc/rancher/k3s/k3s.yaml' (the k3s admin kubeconfig). While this is consistent with the troubleshooting purpose, the access to raw cluster credentials provides a mechanism for data exposure or exfiltration if the agent is compromised.- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it ingests and processes untrusted data from external cluster states and tool outputs. \n * Ingestion points: Output from 'kubectl_get', 'helm_status', and 'ansible_list_playbooks' (SKILL.md). \n * Boundary markers: Absent; there are no instructions to use delimiters or ignore instructions embedded in the output of these tools. \n * Capability inventory: Includes system-level file modification (sudo), playbook execution (ansible_run_playbook), and software installation (helm_upgrade_install). \n * Sanitization: None; the instructions do not mention validating or escaping content retrieved from the cluster before it is processed by the agent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 16, 2026, 03:28 PM
Security Audit — agent-trust-hub — kubernetes-troubleshooting