gke-reliability
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- Standard Command Execution: The skill utilizes
gcloudandkubectlcommands to manage Google Kubernetes Engine resources. These are standard administrative tools used for describing cluster states and applying resource manifests. - Indirect Prompt Injection Surface: The skill facilitates the retrieval of data from the Kubernetes API, which represents an ingestion surface for untrusted data if cluster resources are influenced by external actors.
- Ingestion points: Data enters the context through tools such as
get_cluster,get_k8s_resource, anddescribe_k8s_resource(SKILL.md). - Boundary markers: The skill does not currently implement explicit boundary markers or instructions to ignore potentially embedded instructions within the retrieved Kubernetes resource data.
- Capability inventory: The skill possesses the capability to modify the cluster environment via
apply_k8s_manifestand administrative shell commands (SKILL.md). - Sanitization: The skill relies on default Kubernetes API schema validation and does not specify additional sanitization for content interpolated into the agent's context.
Audit Metadata