managing-k8s-pod-disruption

Pass

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes shell scripts that invoke kubectl and jq to interact with the cluster API.
  • Evidence: Multiple script blocks in SKILL.md use these utilities to discover and filter Kubernetes resources.
  • [DATA_EXFILTRATION]: The skill accesses configuration data from the Kubernetes cluster across all namespaces.
  • Evidence: Commands such as kubectl get pdb --all-namespaces and kubectl get events --all-namespaces expose cluster metadata and status information.
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface by processing potentially untrusted data from the Kubernetes API.
  • Ingestion points: Kubernetes resource names, selectors, and event messages in SKILL.md.
  • Boundary markers: Absent.
  • Capability inventory: Shell command execution via kubectl and jq, and local file write access to /tmp/ in SKILL.md.
  • Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 12, 2026, 04:21 PM
Security Audit — agent-trust-hub — managing-k8s-pod-disruption