skills/google/skills/gke-upgrades/Gen Agent Trust Hub

gke-upgrades

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [Indirect Prompt Injection Surface]: The skill involves reading and processing output from Kubernetes and Google Cloud commands (e.g., kubectl get pods, gcloud container clusters describe). While this is necessary for cluster management, it creates a surface where malicious content in cluster resources could potentially influence the agent. • Ingestion points: Command outputs from kubectl and gcloud as defined in SKILL.md and references/runbook-template.md. • Boundary markers: No explicit instructions are provided to the agent to treat external command output as untrusted. • Capability inventory: The skill utilizes gcloud and kubectl for cluster upgrades, node pool modifications, and resource deletions. • Sanitization: No specific sanitization or validation of command output is performed before processing.
  • [Administrative Command Generation]: The skill generates powerful infrastructure management commands (gcloud container clusters upgrade, kubectl drain, etc.). Users should ensure the agent has the minimum necessary permissions and review all commands before execution to prevent unintended cluster disruptions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 04:45 PM
Security Audit — agent-trust-hub — gke-upgrades