app-service-log-analysis

Pass

Audited by Gen Agent Trust Hub on Aug 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements strict kubeconfig isolation by generating temporary configuration files for each EKS cluster in a dedicated directory and using the --kubeconfig flag, ensuring the user's primary ~/.kube/config is never modified or overwritten.
  • [SAFE]: The dependency discovery mechanism for Kubernetes Secrets is specifically instructed to only retrieve metadata (names and keys) without decoding or accessing sensitive values, minimizing potential exposure of credentials during the deep scan process.
  • [SAFE]: All log collection and analysis operations are conducted using standard AWS CLI and kubectl tools within the user's own environment. There is no evidence of data exfiltration to external or third-party domains.
  • [SAFE]: The skill provides robust cleanup procedures by tracking background PIDs of log streaming processes and ensuring they are terminated upon experiment completion.
  • [SAFE]: The integration with AWS managed services (RDS, ElastiCache, MSK, OpenSearch) uses official AWS CLI commands to check logging status and query CloudWatch logs, adhering to vendor-recommended patterns for observability.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 4, 2026, 01:35 AM
Security Audit — agent-trust-hub — app-service-log-analysis