security-testing
Fail
Audited by Gen Agent Trust Hub on Mar 23, 2026
Risk Level: HIGHCREDENTIALS_UNSAFEDATA_EXFILTRATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill provides a large suite of
kubectl execandcurlcommands designed to probe internal networks, scan services, and interact with sensitive APIs within the cluster environment. It includes patterns for lateral movement and route injection. - [DATA_EXFILTRATION]: Contains explicit instructions and command templates for exfiltrating sensitive cluster data via DNS tunneling by encoding data in subdomains. It also describes methods to extract high-value data from AWS SSM parameters and internal S3 storage.
- [CREDENTIALS_UNSAFE]: References and provides specific methods to access static long-lived credentials, including an AWS IAM access key stored in the
kube-systemnamespace, Cloudflare API tokens, and mesh CA private keys. It also repeatedly uses the~/.kube/dev.yamlconfiguration file for authentication. - [EXTERNAL_DOWNLOADS]: Directs the system to pull and execute external container images (such as
nicolaka/netshoot) from public registries to be used as a base for launching network-based attacks.
Recommendations
- AI detected serious security threats
Audit Metadata