managing-istio-deep

Pass

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes high-privilege CLI tools such as kubectl and istioctl to manage the service mesh. It specifically uses kubectl exec to run curl commands within sidecar containers to access internal Envoy proxy admin interfaces.
  • [DATA_EXFILTRATION]: The skill extracts extensive configuration data, including Envoy config dumps, mesh configuration, and traffic policies. While intended for troubleshooting, this exposes architectural details and potentially sensitive configuration settings from the cluster.
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection (Category 8) as it processes untrusted data from the Kubernetes cluster (resource names, labels, and WasmPlugin URLs) and Envoy status outputs.
  • Ingestion points: Data enters the agent context via kubectl get and envoy_admin calls in SKILL.md which retrieve external resource configurations.
  • Boundary markers: Absent. The skill does not implement delimiters or warnings to prevent the agent from following instructions embedded in the retrieved resource data.
  • Capability inventory: The skill has access to kubectl exec, kubectl get, and istioctl across all internal helper scripts.
  • Sanitization: Uses jq for structural parsing of JSON data, but lacks validation or escaping for string content before it is presented to the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 12, 2026, 04:21 PM
Security Audit — agent-trust-hub — managing-istio-deep