managing-k8s-argocd-deep
Pass
Audited by Gen Agent Trust Hub on Apr 12, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes
kubectlandjqcommands to retrieve deployment information, application health status, and sync errors from theargocdnamespace in a Kubernetes cluster.- [COMMAND_EXECUTION]: Accesses system logs from theargocd-application-controllerand retrieves configuration data from ConfigMaps likeargocd-rbac-cmandargocd-notifications-cmfor auditing purposes.- [PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection (Category 8) by processing untrusted external data. - Ingestion points: External data enters the agent's context through the output of
kubectlcommands when reading resource names, status conditions, and sync result messages inSKILL.md. - Boundary markers: The scripts do not implement delimiters or explicit 'ignore' instructions to distinguish between the cluster data being analyzed and the agent's instructional logic.
- Capability inventory: The skill possesses the capability to execute shell commands via
kubectland read cluster-wide configurations. - Sanitization: There is no evidence of text sanitization or validation performed on the data retrieved from the Kubernetes API before it is passed to the agent for analysis.
Audit Metadata