eks-upgrade-check

Pass

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill uses official AWS CLI and kubectl commands to perform cluster discovery and health checks. These operations are scoped to the cluster management task and do not attempt to access sensitive system files like SSH keys or local environment secrets.
  • [SAFE]: Remote data fetching (via webFetch and WebSearch) is strictly used to retrieve compatibility information and release notes from trusted project documentation (e.g., Istio, Karpenter, cert-manager) and official AWS documentation.
  • [SAFE]: The provided Python script for report conversion (md_to_html.py) uses only Python standard libraries and implements explicit HTML escaping for cluster-derived data (such as labels and images) to prevent cross-site scripting (XSS) or injection in the generated reports.
  • [SAFE]: The instructions include explicit warnings and procedures for 'Account ID hygiene' to ensure sensitive information is masked before reports are shared.
  • [SAFE]: No persistence mechanisms, privilege escalation attempts, or obfuscated code were detected in the skill's instructions or supporting scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 21, 2026, 06:52 PM
Security Audit — agent-trust-hub — eks-upgrade-check