skills/google/skills/gke-reliability/Gen Agent Trust Hub

gke-reliability

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • Standard Command Execution: The skill utilizes gcloud and kubectl commands to manage Google Kubernetes Engine resources. These are standard administrative tools used for describing cluster states and applying resource manifests.
  • Indirect Prompt Injection Surface: The skill facilitates the retrieval of data from the Kubernetes API, which represents an ingestion surface for untrusted data if cluster resources are influenced by external actors.
  • Ingestion points: Data enters the context through tools such as get_cluster, get_k8s_resource, and describe_k8s_resource (SKILL.md).
  • Boundary markers: The skill does not currently implement explicit boundary markers or instructions to ignore potentially embedded instructions within the retrieved Kubernetes resource data.
  • Capability inventory: The skill possesses the capability to modify the cluster environment via apply_k8s_manifest and administrative shell commands (SKILL.md).
  • Sanitization: The skill relies on default Kubernetes API schema validation and does not specify additional sanitization for content interpolated into the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 05:39 AM
Security Audit — agent-trust-hub — gke-reliability