skills/joelhooks/joelclaw/k8s/Gen Agent Trust Hub

k8s

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONPERSISTENCEEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a runtime contract for an 'Agent Runner' that creates Kubernetes Jobs to execute sandboxed tasks. These Jobs ingest instructions through base64-encoded environment variables.
  • Ingestion points: The TASK_PROMPT_B64 and VERIFICATION_COMMANDS_B64 environment variables in SKILL.md are used to pass instructions into the sandboxed job.
  • Boundary markers: The current specification does not detail explicit boundary markers or instructions for the runner to ignore malicious directives embedded within the provided tasks.
  • Capability inventory: The sandboxed Jobs possess significant capabilities, including full access to a workspace, the Bun runtime, Git operations, and the ability to execute an AGENT_PROGRAM and subsequent verification commands.
  • Sanitization: Instructions are decoded from base64; however, there is no mention of sanitization or safety filtering of the resulting content before execution within the pod.
  • [COMMAND_EXECUTION]: The skill makes extensive use of administrative CLI tools to manage the cluster environment. This includes kubectl for resource management, talosctl for node operations, and docker/colima for the underlying virtualization layer. The skill instructions frequently involve executing shell commands for health checks, debugging, and data recovery (e.g., using redis-check-aof inside a recovery pod).
  • [PRIVILEGE_ESCALATION]: The skill performs high-privilege operations necessary for infrastructure management. This includes using sudo for loading kernel modules (modprobe) and service management within the Colima VM. It also explicitly deploys privileged Kubernetes workloads that require access to /dev/kvm for Firecracker microVM support.
  • [PERSISTENCE]: The skill implements automated persistence and recovery mechanisms by installing multiple launchd services into the system domain. These services (e.g., com.joel.colima, com.joel.k8s-reboot-heal) ensure the virtualization environment, cluster networking, and worker components are automatically restored and maintained across system reboots.
  • [EXTERNAL_DOWNLOADS]: The skill instructions facilitate the setup of cluster infrastructure by downloading configuration manifests from external sources.
  • Evidence: Fetches the local-path-storage manifest from Rancher's official GitHub repository and the metrics-server manifest from the official kubernetes-sigs repository.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 05:03 PM
Security Audit — agent-trust-hub — k8s