gke-platform-security

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • Command Execution Patterns: The skill documents several command-line patterns using gcloud and kubectl to manage cluster settings and IAM policies. These are standard administrative actions for GKE platform security and use clear placeholders for project-specific variables.
  • Indirect Prompt Injection Surface: The skill is designed to ingest and process cluster metadata and Kubernetes resource manifests. Processing data from external environments is a standard security consideration, as instructions could potentially be embedded in these external sources. 1. Ingestion points: Cluster configuration details and resource manifests retrieved via platform tools (SKILL.md). 2. Boundary markers: No explicit delimiters are specified in the instructional text for tool outputs. 3. Capability inventory: The skill utilizes tools capable of modifying cluster states and applying resource manifests (gke:update_cluster, k8s:apply_k8s_manifest). 4. Sanitization: The skill relies on the inherent validation provided by the cloud platform's CLI and API tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 05:42 PM
Security Audit — agent-trust-hub — gke-platform-security