coreweave-install-auth

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides standard documentation for configuring Kubernetes access and uses placeholders for credentials rather than hardcoded secrets.
  • [SAFE]: The skill follows secret management best practices by recommending storage in local environment files rather than insecure locations.
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to read and process output from Kubernetes pod logs. 1. Ingestion points: pod logs via kubectl logs (SKILL.md). 2. Boundary markers: none present. 3. Capability inventory: Read, Write, Edit, and Bash. 4. Sanitization: none. This attack surface is inherent to the skill's primary purpose of infrastructure management.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 03:45 AM
Security Audit — agent-trust-hub — coreweave-install-auth