skills/google/skills/gke-basics/Gen Agent Trust Hub

gke-basics

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • Command Execution for Cluster Management: The skill utilizes gcloud, kubectl, and specialized Model Context Protocol (MCP) tools to perform administrative tasks. These include creating and updating clusters, managing node pools, and executing commands within pods (kubectl exec). These actions are consistent with the skill's role as a GKE management interface.
  • Official External Dependencies: The instructions reference and provide installation commands for official Kubernetes client libraries (e.g., pip install kubernetes, npm install @kubernetes/client-node). These are well-known, trusted libraries used for programmatic interaction with Kubernetes APIs.
  • Sensitive File Access for Configuration: The skill's code examples involve loading Kubernetes configurations from standard local paths (e.g., ~/.kube/config). This is the expected method for authenticating a client to a cluster and is used locally for session management.
  • Indirect Prompt Injection Surface: The skill includes tools for applying YAML manifests (apply_k8s_manifest, kubectl apply) and patching resources. Since these tools process external configuration data, there is a standard attack surface for indirect prompt injection if an attacker provides a malicious manifest. The skill mitigates this risk by recommending best practices like Workload Identity and dry-run operations.
  • Trusted Infrastructure and References: All external links and resources (e.g., cloud.google.com, github.com/kubernetes-client/java, registry.terraform.io) point to official Google Cloud or well-known industry repositories, ensuring that all downloads and references originate from trusted sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 12:02 AM
Security Audit — agent-trust-hub — gke-basics