gke-workload-scaling-troubleshooting

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [Standard Diagnostic Tooling]: The skill utilizes established command-line utilities like kubectl and gcloud to gather diagnostic information from the cluster environment (SKILL.md).
  • [Read-Only Operation]: The instructions prioritize data retrieval and explicitly direct the agent to propose fixes for manual review rather than applying live changes to the infrastructure, which is a proactive safety measure (SKILL.md).
  • [Trusted Documentation References]: All external links point to official technical documentation from Google Cloud and the Kubernetes project (SKILL.md).
  • [Indirect Prompt Injection Surface]: The skill ingests and processes output from cluster diagnostic commands and logs, which constitutes a potential injection surface.
  • Ingestion points: Data is retrieved from commands like kubectl describe, kubectl get -o yaml, and Cloud Logging queries (SKILL.md).
  • Boundary markers: The skill establishes a "read-only diagnostics boundary" and requires presenting results as reviewable changes (SKILL.md).
  • Capability inventory: The skill uses kubectl, gcloud, and jq for diagnostics throughout the resolution branches (SKILL.md).
  • Sanitization: No explicit content sanitization or filtering logic is specified for the raw data ingested from the cluster.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 07:52 PM
Security Audit — agent-trust-hub — gke-workload-scaling-troubleshooting