gke-observability

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • Command Execution: The skill provides several gcloud and kubectl commands to update cluster configurations, read logs, and view resource usage.
  • Evidence: Commands like gcloud container clusters update and gcloud logging read are included in SKILL.md to enable observability features and query telemetry data.
  • Context: These commands are standard administrative tools for Google Cloud Platform and are necessary for the skill's primary purpose of configuring GKE observability.
  • Indirect Prompt Injection Surface: The skill includes tools and commands that ingest external, potentially untrusted data from Kubernetes logs.
  • Ingestion points: The skill utilizes get_k8s_logs and gcloud logging read as described in SKILL.md.
  • Boundary markers: No explicit delimiters or instructions are provided to the agent to treat the content of logs as untrusted data.
  • Capability inventory: The skill possesses the capability to modify cluster configurations via gcloud container clusters update.
  • Sanitization: No specific sanitization or filtering of log content is implemented.
  • Context: While this creates an ingestion surface for indirect prompt injection, it is an inherent property of any observability or log-processing tool. The risk is considered low and associated with the primary legitimate purpose of the skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 05:39 AM
Security Audit — agent-trust-hub — gke-observability