kubernetes-specialist
Pass
Audited by Gen Agent Trust Hub on Apr 29, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection (Category 8) as it is designed to process untrusted data from production environments.
- Ingestion points: The 'Development Workflow' in SKILL.md specifies that the agent should 'Review cluster configuration', 'Analyze workload patterns', and perform 'Log aggregation'. These sources can be controlled or influenced by an attacker.
- Boundary markers: The skill does not provide instructions to use delimiters or ignore potentially malicious instructions embedded within the cluster data it retrieves.
- Capability inventory: The skill is intended to manage 'Control plane design', 'RBAC configuration', and 'Workload orchestration', implying the host agent has high-privilege access to the Kubernetes API and underlying infrastructure.
- Sanitization: There are no requirements or steps provided to sanitize, validate, or escape the content of logs or manifests before they are incorporated into the agent's context.
Audit Metadata