managing-k8s-sealed-secrets
Warn
Audited by Gen Agent Trust Hub on Apr 12, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes multiple shell commands using the
kubectlCLI to interact with the Kubernetes API. These commands perform discovery and status analysis of cluster resources including deployments, pods, and custom resource definitions. - [DATA_EXFILTRATION]: The skill specifically targets and accesses sensitive Kubernetes Secret resources in the
kube-systemnamespace that contain private sealing keys (sealedsecrets.bitnami.com/sealed-secrets-key). These keys are the root of trust for secret encryption in the cluster. Although the included scripts currently only output metadata such as names and creation dates, the permission level required to run these commands exposes highly sensitive cryptographic data. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection (Category 8) because it ingests and processes untrusted data from the Kubernetes environment.
- Ingestion points: Discovery and analysis commands in
SKILL.mdthat retrieve resource metadata and status fields usingkubectlwith JSON or custom-column output formats. - Boundary markers: No boundary markers or specific "ignore embedded instructions" delimiters are used to wrap the ingested resource data.
- Capability inventory: The skill has the capability to execute arbitrary shell commands and read cluster-wide secrets via the
kubectltool. - Sanitization: There is no evidence of sanitization, escaping, or schema validation for the data ingested from the cluster before it is presented to the agent's context.
Audit Metadata