gitops-cluster-debug

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted data from a live Kubernetes environment, which could be exploited to influence agent behavior.
  • Ingestion points: The agent retrieves pod logs using get_kubernetes_logs and resource definitions using get_kubernetes_resources (SKILL.md).
  • Boundary markers: There are no explicit instructions or delimiters provided to ensure the agent ignores or sanitizes potential instructions embedded within the data it analyzes.
  • Capability inventory: The skill possesses significant capabilities, including the ability to apply manifests to the cluster using apply_kubernetes_manifest and switch contexts via set_kubeconfig_context.
  • Sanitization: No sanitization logic is defined for the data retrieved from the cluster before it is used for root cause analysis or reporting.
  • [EXTERNAL_DOWNLOADS]: The skill includes schema references and documentation links to the official Flux CD project infrastructure.
  • Evidence: Multiple schema files in the assets/schemas/ directory reference the official Flux CD (github.com/fluxcd/flux2) and Flux Operator (github.com/controlplaneio-fluxcd/flux-operator) repositories as sources for validation metadata.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 03:08 PM
Security Audit — agent-trust-hub — gitops-cluster-debug