gke-upgrades
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [Indirect Prompt Injection Surface]: The skill involves reading and processing output from Kubernetes and Google Cloud commands (e.g.,
kubectl get pods,gcloud container clusters describe). While this is necessary for cluster management, it creates a surface where malicious content in cluster resources could potentially influence the agent. • Ingestion points: Command outputs fromkubectlandgcloudas defined inSKILL.mdandreferences/runbook-template.md. • Boundary markers: No explicit instructions are provided to the agent to treat external command output as untrusted. • Capability inventory: The skill utilizesgcloudandkubectlfor cluster upgrades, node pool modifications, and resource deletions. • Sanitization: No specific sanitization or validation of command output is performed before processing. - [Administrative Command Generation]: The skill generates powerful infrastructure management commands (
gcloud container clusters upgrade,kubectl drain, etc.). Users should ensure the agent has the minimum necessary permissions and review all commands before execution to prevent unintended cluster disruptions.
Audit Metadata