managing-k8s-argocd-deep

Pass

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes kubectl and jq commands to retrieve deployment information, application health status, and sync errors from the argocd namespace in a Kubernetes cluster.- [COMMAND_EXECUTION]: Accesses system logs from the argocd-application-controller and retrieves configuration data from ConfigMaps like argocd-rbac-cm and argocd-notifications-cm for auditing purposes.- [PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection (Category 8) by processing untrusted external data.
  • Ingestion points: External data enters the agent's context through the output of kubectl commands when reading resource names, status conditions, and sync result messages in SKILL.md.
  • Boundary markers: The scripts do not implement delimiters or explicit 'ignore' instructions to distinguish between the cluster data being analyzed and the agent's instructional logic.
  • Capability inventory: The skill possesses the capability to execute shell commands via kubectl and read cluster-wide configurations.
  • Sanitization: There is no evidence of text sanitization or validation performed on the data retrieved from the Kubernetes API before it is passed to the agent for analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 12, 2026, 04:21 PM
Security Audit — agent-trust-hub — managing-k8s-argocd-deep