gke-observability
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- Command Execution: The skill provides several
gcloudandkubectlcommands to update cluster configurations, read logs, and view resource usage. - Evidence: Commands like
gcloud container clusters updateandgcloud logging readare included inSKILL.mdto enable observability features and query telemetry data. - Context: These commands are standard administrative tools for Google Cloud Platform and are necessary for the skill's primary purpose of configuring GKE observability.
- Indirect Prompt Injection Surface: The skill includes tools and commands that ingest external, potentially untrusted data from Kubernetes logs.
- Ingestion points: The skill utilizes
get_k8s_logsandgcloud logging readas described inSKILL.md. - Boundary markers: No explicit delimiters or instructions are provided to the agent to treat the content of logs as untrusted data.
- Capability inventory: The skill possesses the capability to modify cluster configurations via
gcloud container clusters update. - Sanitization: No specific sanitization or filtering of log content is implemented.
- Context: While this creates an ingestion surface for indirect prompt injection, it is an inherent property of any observability or log-processing tool. The risk is considered low and associated with the primary legitimate purpose of the skill.
Audit Metadata