k8s-workload-inventory

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill defines read-only monitoring capabilities for Kubernetes clusters. It explicitly instructs the agent that 'Secrets are denied', which is a crucial safety measure to prevent accidental exposure of sensitive credentials.- [SAFE]: The skill requires standard tools like kubectl and relies on K8S_KUBECONFIG for configuration, following established industry practices for cluster access.- [SAFE]: No obfuscation, prompt injection attempts, or unauthorized persistence mechanisms were identified. The instructions focus on accurate, scope-aware reporting of pod statuses and events.- [SAFE]: While the skill ingests data from external cluster status (potential indirect prompt injection surface via pod names or events), the read-only restriction and structured reporting requirements provide adequate safety for the intended monitoring use case.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 09:47 AM
Security Audit — agent-trust-hub — k8s-workload-inventory