kubernetes-patterns

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides a variety of kubectl commands for debugging and managing workloads. These are standard operations for a Kubernetes-oriented skill and include placeholders for namespaced resources.
  • [REMOTE_CODE_EXECUTION]: The skill references container images from ghcr.io (GitHub Container Registry), which is a well-known and trusted service. No arbitrary script execution from unknown sources was detected.
  • [CREDENTIALS_UNSAFE]: While the skill demonstrates how to handle Kubernetes Secrets, it uses benign, Base64-encoded placeholders for educational purposes (e.g., db-password: czNjcjN0). It correctly advises against storing plaintext secrets in ConfigMaps and recommends external secret managers for production use.
  • [EXTERNAL_DOWNLOADS]: The skill links to official documentation for established tools like Bitnami's Sealed Secrets and the External Secrets Operator. These are well-known and reputable services in the Kubernetes ecosystem.
  • [SAFE]: The content explicitly promotes security hardening, including running containers as non-root users, setting a read-only root filesystem, dropping capabilities, and using dedicated ServiceAccounts with automountServiceAccountToken: false to minimize the attack surface.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:41 PM
Security Audit — agent-trust-hub — kubernetes-patterns