kubernetes-specialist

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFEPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to download configuration manifests and installation binaries from well-known external sources. Each reference targets official repositories or project sites.
  • Evidence: references/gitops.md includes kubectl apply -n argocd -f https://raw.githubusercontent.com/argoproj/argo-cd/stable/manifests/install.yaml.
  • Evidence: references/multi-cluster.md includes curl -L https://github.com/kubernetes-sigs/cluster-api/releases/download/v1.6.0/clusterctl-linux-amd64 -o clusterctl.
  • [REMOTE_CODE_EXECUTION]: Instructions for installing various infrastructure tools involve piping remote scripts directly to a shell environment. These are standard official installation methods for the respective projects.
  • Evidence: references/service-mesh.md contains curl -L https://istio.io/downloadIstio | sh -.
  • Evidence: references/service-mesh.md contains curl --proto '=https' --tlsv1.2 -sSfL https://run.linkerd.io/install | sh.
  • Evidence: references/gitops.md contains curl -Ls https://get.submariner.io | bash.
  • [COMMAND_EXECUTION]: The skill documents the use of powerful administrative commands necessary for cluster troubleshooting and node management.
  • Evidence: references/troubleshooting.md includes commands for node debugging such as kubectl debug node/node-01 -it --image=ubuntu:latest -- chroot /host.
  • Evidence: references/troubleshooting.md and other files frequently use kubectl exec to run commands inside containers.
  • [CREDENTIALS_UNSAFE]: Reference documentation includes example secrets and base64-encoded credentials for illustrative purposes.
  • Evidence: references/configuration.md contains example Base64 strings like bXl1c2VyOm15cGFzc3dvcmQ= (decodes to myuser:mypassword).
  • Evidence: references/configuration.md includes a generic API key example sk-1234567890abcdef.
  • [PROMPT_INJECTION]: As an infrastructure management skill, it ingests and processes untrusted data (like application requirements) to generate YAML manifests, creating a surface for indirect prompt injection.
  • Ingestion points: User requirements and workload descriptions are processed by the agent from user input and referenced files.
  • Boundary markers: The skill does not explicitly define markers or system instructions to ignore embedded instructions within processed data.
  • Capability inventory: The skill has broad capabilities to write manifest files and execute administrative commands via kubectl.
  • Sanitization: There is no explicit sanitization or validation logic described for external content before interpolation into manifests.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 03:58 PM
Security Audit — agent-trust-hub — kubernetes-specialist