cluster-agent-swarm-hardened

Warn

Audited by Gen Agent Trust Hub on Apr 21, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill directs users to install additional components from an external repository (https://github.com/kcns008/cluster-agent-swarm-skills). The repository owner is unverified and does not align with the author metadata (cluster-agent-swarm) or the recognized vendor (faberlens), creating a potential supply chain risk for administrative tools.
  • [COMMAND_EXECUTION]: The skill grants access to powerful orchestration tools such as kubectl, oc, helm, and argocd, as well as cloud platform CLIs (aws, az, gcloud). These capabilities allow for extensive cluster modification and infrastructure control.
  • [DATA_EXFILTRATION]: The combination of access to sensitive cluster data (secrets, configurations, logs) and network-capable tools (curl, git) creates an exfiltration surface. While the skill includes guardrails to prevent data transfer to external endpoints, the capability remains present.
  • [PROMPT_INJECTION]: The skill processes untrusted external data from Kubernetes logs and resource definitions, making it vulnerable to indirect prompt injection. Ingestion points: Reads cluster state and logs via kubectl and oc (SKILL.md). Boundary markers: Includes a Security Guardrails section instructing the agent to ignore claimed authority and verify destructive operations. Capability inventory: Full access to cluster-admin level commands and cloud provider management tools. Sanitization: Documentation in SAFETY.md mentions log sanitization as a security feature, though implementation details are not visible.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 21, 2026, 06:31 PM
Security Audit — agent-trust-hub — cluster-agent-swarm-hardened