kubernetes-specialist
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions to download and install various Kubernetes utilities from their official sources.
- Official ArgoCD manifest: "https://raw.githubusercontent.com/argoproj/argo-cd/stable/manifests/install.yaml" in "references/gitops.md".
- Official Istio installer: "https://istio.io/downloadIstio" in "references/service-mesh.md".
- Official Linkerd installer: "https://run.linkerd.io/install" in "references/service-mesh.md".
- Official Submariner script: "https://get.submariner.io" in "references/multi-cluster.md".
- Kubernetes-sigs Cluster API binary: "https://github.com/kubernetes-sigs/cluster-api/releases/download/v1.6.0/clusterctl-linux-amd64" in "references/multi-cluster.md".
- [COMMAND_EXECUTION]: The troubleshooting and installation guides contain shell commands, including piped-execution patterns for installing infrastructure tools.
- Installation scripts for Istio, Linkerd, and Submariner use "curl | sh" or "curl | bash" patterns.
- Numerous "kubectl" commands for cluster management and debugging are provided in "SKILL.md" and "references/troubleshooting.md".
- [INDIRECT_PROMPT_INJECTION]: The skill includes instructions for analyzing container logs and cluster events.
- Ingestion points: "kubectl logs" and "kubectl describe" in "references/troubleshooting.md" ingest untrusted data from running containers.
- Boundary markers: None explicitly defined for log analysis.
- Capability inventory: The skill uses "kubectl" to interact with the cluster and perform management tasks.
- Sanitization: No specific sanitization or escaping of log content is mentioned.
- [CREDENTIALS_UNSAFE]: Reference files contain example secrets and credential placeholders.
- Placeholder API keys and passwords (e.g., "sk-1234567890abcdef") are present in "references/configuration.md" as instructional examples.
- The skill enforces security best practices by recommending the use of "Secret" and "SealedSecret" resources for sensitive data management.
Audit Metadata