k8s-workload-packaging-and-manifest
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill enforces a security-context baseline for all generated pod templates, requiring 'runAsNonRoot: true', 'readOnlyRootFilesystem: true', 'allowPrivilegeEscalation: false', and the dropping of all capabilities.
- [SAFE]: Credential security is maintained through explicit instructions to use Secret references (names only) and ConfigMaps, strictly forbidding the inlining of secret values within manifests.
- [SAFE]: Validation steps utilize standard Kubernetes tooling such as 'kubectl apply --dry-run' or 'kubeconform' to verify manifest schema and policy compliance before finalization.
- [SAFE]: The skill implements a 'handoff' architecture, delegating high-privilege or sensitive tasks like RBAC depth, network policy, and image hardening to specific specialized archetypes rather than attempting to perform them autonomously.
Audit Metadata