gke-cluster-creation
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- Infrastructure Command Execution: The skill plans and executes GKE cluster provisioning using
gcloudCLI commands and Model Context Protocol (MCP) tools. These high-privilege operations are central to the skill's purpose and are managed through structured templates.\n- Dynamic Configuration Assembly: The agent generates shell commands and JSON payloads by interpolating user-provided inputs like project IDs and cluster names. A key safety feature is the requirement for the agent to present these configurations to the user for explicit approval before execution.\n- Security Hardening Defaults: The provided 'Golden Path' templates include security-focused configurations, such as private control planes and Shielded GKE Nodes, which help maintain a secure environment by default.\n- Indirect Prompt Injection Surface: This skill ingests untrusted user data (project IDs, regions, cluster names) from the agent context. These inputs are interpolated into tool calls (create_cluster) and shell commands (gcloud). While explicit sanitization logic is not defined within the skill instructions, the risk is addressed by the mandatory requirement for human-in-the-loop review of all generated configurations prior to execution, and the use of pre-defined security-hardened templates.
Audit Metadata