kubernetes-patterns
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill provides a variety of
kubectlcommands for debugging and managing workloads. These are standard operations for a Kubernetes-oriented skill and include placeholders for namespaced resources. - [REMOTE_CODE_EXECUTION]: The skill references container images from
ghcr.io(GitHub Container Registry), which is a well-known and trusted service. No arbitrary script execution from unknown sources was detected. - [CREDENTIALS_UNSAFE]: While the skill demonstrates how to handle Kubernetes Secrets, it uses benign, Base64-encoded placeholders for educational purposes (e.g.,
db-password: czNjcjN0). It correctly advises against storing plaintext secrets in ConfigMaps and recommends external secret managers for production use. - [EXTERNAL_DOWNLOADS]: The skill links to official documentation for established tools like Bitnami's Sealed Secrets and the External Secrets Operator. These are well-known and reputable services in the Kubernetes ecosystem.
- [SAFE]: The content explicitly promotes security hardening, including running containers as non-root users, setting a read-only root filesystem, dropping capabilities, and using dedicated ServiceAccounts with
automountServiceAccountToken: falseto minimize the attack surface.
Audit Metadata