kubernetes-specialist

Pass

Audited by Gen Agent Trust Hub on Apr 29, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection (Category 8) as it is designed to process untrusted data from production environments.
  • Ingestion points: The 'Development Workflow' in SKILL.md specifies that the agent should 'Review cluster configuration', 'Analyze workload patterns', and perform 'Log aggregation'. These sources can be controlled or influenced by an attacker.
  • Boundary markers: The skill does not provide instructions to use delimiters or ignore potentially malicious instructions embedded within the cluster data it retrieves.
  • Capability inventory: The skill is intended to manage 'Control plane design', 'RBAC configuration', and 'Workload orchestration', implying the host agent has high-privilege access to the Kubernetes API and underlying infrastructure.
  • Sanitization: There are no requirements or steps provided to sanitize, validate, or escape the content of logs or manifests before they are incorporated into the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 29, 2026, 10:54 AM
Security Audit — agent-trust-hub — kubernetes-specialist