managing-istio

Pass

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The bash functions and scripts in SKILL.md (including istio_get, istio_cmd, and proxy debugging scripts) use positional parameters and variables directly in shell calls to kubectl and istioctl. This lack of parameter sanitization constitutes a command injection vulnerability surface.
  • Ingestion points: Variable inputs for $resource, $POD, $NS, and $SERVICE within the provided shell scripts.
  • Boundary markers: No markers or delimiters are present to isolate interpolated values from the command strings.
  • Capability inventory: The skill utilizes kubectl and istioctl to interact with the service mesh, which involves reading and potentially modifying security-critical configurations such as mTLS and authorization policies.
  • Sanitization: There is no evidence of validation or shell-escaping for the variables used in commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 12, 2026, 04:21 PM
Security Audit — agent-trust-hub — managing-istio