kubernetes-specialist
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches installation manifests and scripts from official project repositories including the Argo Project on GitHub, the Istio project website, and the Linkerd installation service. These represent standard installation procedures for well-known and established open-source infrastructure tools.
- [COMMAND_EXECUTION]: The skill provides numerous examples of shell commands and
kubectloperations intended for cluster management, CLI installation (e.g.,clusterctl), and resource debugging. These commands are consistent with the skill's primary purpose as a Kubernetes specialist. - [INDIRECT_PROMPT_INJECTION]: The skill contains an attack surface for indirect injection by ingesting and processing untrusted external data.
- Ingestion points: The skill reads external data through tools like
kubectl logsandkubectl describe, as documented inreferences/troubleshooting.mdandSKILL.md. - Boundary markers: No specific boundary markers or instructions to ignore embedded instructions are present in the command examples.
- Capability inventory: The skill utilizes extensive capabilities including shell command execution (
kubectl,curl,bash) and file system operations. - Sanitization: No explicit sanitization or filtering of external container logs or event data is performed before displaying them to the user or agent context.
Audit Metadata