k8s-workload-inventory
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill defines read-only monitoring capabilities for Kubernetes clusters. It explicitly instructs the agent that 'Secrets are denied', which is a crucial safety measure to prevent accidental exposure of sensitive credentials.- [SAFE]: The skill requires standard tools like
kubectland relies onK8S_KUBECONFIGfor configuration, following established industry practices for cluster access.- [SAFE]: No obfuscation, prompt injection attempts, or unauthorized persistence mechanisms were identified. The instructions focus on accurate, scope-aware reporting of pod statuses and events.- [SAFE]: While the skill ingests data from external cluster status (potential indirect prompt injection surface via pod names or events), the read-only restriction and structured reporting requirements provide adequate safety for the intended monitoring use case.
Audit Metadata