inspect
Pass
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill ingests untrusted metadata from a Kubernetes cluster, creating a surface for indirect prompt injection if resource names, network annotations, or event messages contain malicious instructions.
- Ingestion points: Kubernetes pod details, events, and resource configurations accessed via MCP tools in SKILL.md.
- Boundary markers: The skill does not use delimiters or instructions to ignore embedded commands within the retrieved data.
- Capability inventory: The agent has access to multiple Kubernetes MCP tools for listing and retrieving detailed resource information.
- Sanitization: There is no defined process for sanitizing or validating the data returned from the cluster before it is processed by the agent.
Audit Metadata