k8s-supply-chain-and-image-hardening
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: No instructions were found that attempt to bypass safety filters, override system prompts, or extract internal instructions. The skill's instructions are strictly limited to the stated purpose of Kubernetes security hardening.
- [DATA_EXFILTRATION]: No evidence of hardcoded credentials, sensitive file access (e.g., SSH keys, AWS credentials), or unauthorized network operations was found. The skill correctly instructs the use of OIDC/Keyless signing for
cosignto avoid long-lived secret management. - [OBFUSCATION]: The skill's content was checked for Base64 encoding, zero-width characters, homoglyphs, and other obfuscation techniques; no such patterns were detected.
- [REMOTE_CODE_EXECUTION]: While the skill mentions using tools like
cosign,syft,trivy, andgrype, these are standard industry tools for container security. There are no patterns involving execution of remote scripts via pipe-to-shell or similar dangerous methods. - [COMMAND_EXECUTION]: The skill provides templates for standard Kubernetes CLI tools. These commands are intended for output as hardening artifacts and do not represent arbitrary or dangerous command execution by the agent platform itself.
- [DYNAMIC_CONTEXT_INJECTION]: The
SKILL.mdwas analyzed for the!commandsyntax; no such dynamic injection patterns were found.
Audit Metadata