gitops-knowledge

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external data from Kubernetes clusters and GitOps repositories, creating a potential surface for indirect prompt injection. 1. Ingestion points: MCP tools (e.g., get_kubernetes_resources, get_kubernetes_logs) and CLI discovery tools (flux schema discover). 2. Boundary markers: The skill instructions recommend using human review and read-only modes for the MCP server, though they do not specify explicit data delimiters in prompts. 3. Capability inventory: The skill can apply Kubernetes manifests, reconcile Flux sources, and execute schema validation tools. 4. Sanitization: No explicit sanitization or filtering of external content is defined in the instructions.
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions for installing the Flux CLI, various plugins, and Helm charts from official vendor sources, including Homebrew taps, OCI registries (ghcr.io/fluxcd), and GitHub release pages. These references target trusted organizations and well-known services and are documented neutrally.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 11:03 PM
Security Audit — agent-trust-hub — gitops-knowledge