eks-operation-review

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from a live EKS cluster—such as pod metadata, environment variables, and event logs—to generate operational assessments. While this constitutes processing untrusted input that could theoretically contain malicious instructions, the risk is inherent to the auditing purpose and is managed by the skill's structured workflow and sanitized output processing.
  • Ingestion points: EKS and Kubernetes resource metadata (Pods, ServiceAccounts, IAM roles, event messages) retrieved via MCP tools or CLI.
  • Boundary markers: The instructions guide the agent to compile data into predefined Markdown report sections and tables.
  • Capability inventory: Workspace file writing and execution of the bundled report_to_html.py script.
  • Sanitization: The report_to_html.py script implements HTML escaping and URL scheme validation (restricting links to http, https, and mailto) for the generated report.
  • [COMMAND_EXECUTION]: The skill includes and utilizes a local Python script, report_to_html.py, to convert Markdown findings into a styled HTML format. This is a standard functional component provided within the skill package for report generation.
  • [SAFE]: The skill is provided by a recognized vendor and incorporates security-conscious instructions, specifically warning the agent to avoid reading the content of Kubernetes Secrets while checking for their presence.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 09:57 AM