atmos-kubernetes
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external Kubernetes manifests which could contain instructions. Ingestion points: files in component paths and inline YAML manifests (SKILL.md). Boundary markers: none specified to delimit untrusted data. Capability inventory: performs Kubernetes API operations (apply, deploy, delete) and executes shell commands via hooks. Sanitization: no evidence of sanitization or validation of manifest content.
- [COMMAND_EXECUTION]: The skill provides a lifecycle hook system (e.g., after.kubernetes.apply) that allows the execution of arbitrary shell commands.
- [EXTERNAL_DOWNLOADS]: The provision.targets feature for GitOps delivery allows cloning from and pushing to external Git repositories.
- [CREDENTIALS_UNSAFE]: The skill manages access to sensitive kubeconfig files (e.g., /tmp/kubeconfig) and processes Kubernetes Secrets as part of its core deployment functionality.
Audit Metadata