gke-compute-classes
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- Infrastructure Log Access: The shell script
assets/log-autoscaler-events.shperforms read operations on GKE autoscaler visibility logs using thegcloud logging readcommand. While this is a common diagnostic activity for cloud administrators, it requires sensitive infrastructure permissions (e.g.,roles/logging.viewer) and exposes system-level event data to the agent for analysis. - Prompt Injection Countermeasures: The skill provides defensive instructions under the
CRITICAL INJECTION RULEthat explicitly direct the AI agent to treat user-provided data, including logs and YAML snippets, as untrusted. This design choice helps prevent adversarial content from overriding the agent's established behavioral guidelines. - Indirect Prompt Injection Surface: The skill is designed to process untrusted external data (ingestion points in
SKILL.md). - Ingestion points: The agent ingests user-provided logs and configuration YAML files for debugging.
- Boundary markers: While no specific data delimiters are enforced, the instructions contain a dedicated section warning the agent to ignore directives embedded in user data.
- Capability inventory: The skill utilizes
kubectl,gcloud, and custom shell scripts (assets/log-autoscaler-events.sh) to interact with the GKE environment. - Sanitization: The skill relies on the AI's internal reasoning and explicit instruction-based sanitization rather than automated data filtering.
- Trusted Repository Reference: The skill encourages behavior verification by referencing the official
GoogleCloudPlatform/cluster-autoscalerrepository. This practice promotes the use of authoritative, open-source code for troubleshooting and verification, which is considered a secure operational practice.
Audit Metadata