gke-compute-classes

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • Infrastructure Log Access: The shell script assets/log-autoscaler-events.sh performs read operations on GKE autoscaler visibility logs using the gcloud logging read command. While this is a common diagnostic activity for cloud administrators, it requires sensitive infrastructure permissions (e.g., roles/logging.viewer) and exposes system-level event data to the agent for analysis.
  • Prompt Injection Countermeasures: The skill provides defensive instructions under the CRITICAL INJECTION RULE that explicitly direct the AI agent to treat user-provided data, including logs and YAML snippets, as untrusted. This design choice helps prevent adversarial content from overriding the agent's established behavioral guidelines.
  • Indirect Prompt Injection Surface: The skill is designed to process untrusted external data (ingestion points in SKILL.md).
  • Ingestion points: The agent ingests user-provided logs and configuration YAML files for debugging.
  • Boundary markers: While no specific data delimiters are enforced, the instructions contain a dedicated section warning the agent to ignore directives embedded in user data.
  • Capability inventory: The skill utilizes kubectl, gcloud, and custom shell scripts (assets/log-autoscaler-events.sh) to interact with the GKE environment.
  • Sanitization: The skill relies on the AI's internal reasoning and explicit instruction-based sanitization rather than automated data filtering.
  • Trusted Repository Reference: The skill encourages behavior verification by referencing the official GoogleCloudPlatform/cluster-autoscaler repository. This practice promotes the use of authoritative, open-source code for troubleshooting and verification, which is considered a secure operational practice.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 05:39 AM
Security Audit — agent-trust-hub — gke-compute-classes