kubernetes

Pass

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill is purely informational, providing instructions on how to use standard Kubernetes tools like kubectl and manage cluster resources such as Deployments and Services.- [NO_CODE]: No scripts, binaries, or automated installation commands are included with this skill.- [DATA_EXPOSURE]: The instructions correctly advise the use of Kubernetes Secrets for sensitive information and mention the requirement of a kubeconfig for cluster access, adhering to standard security best practices.- [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves interpreting Kubernetes resource definitions and command outputs (e.g., kubectl logs, kubectl describe). This creates an attack surface where malicious content within these external sources could potentially influence agent behavior.
  • Ingestion points: Kubernetes YAML files and command outputs (logs, describe).
  • Boundary markers: None specified in the skill body.
  • Capability inventory: File system access (reading YAML) and shell command execution (kubectl).
  • Sanitization: No explicit sanitization or validation steps are provided for the processed data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 23, 2026, 04:08 PM
Security Audit — agent-trust-hub — kubernetes