external-urls

Warn

Audited by Gen Agent Trust Hub on May 13, 2026

Risk Level: MEDIUMCREDENTIALS_UNSAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill exposes specific local file system paths to sensitive Kubernetes authentication files (kubeconfigs) in both SKILL.md and references/urls-detail.md. Examples include ~/.kube/aks-rg-hypera-cafehyna-hub-config and ~/.kube/aks-rg-hypera-cafehyna-dev-config. These files contain authentication tokens or certificates used to gain cluster access.
  • [COMMAND_EXECUTION]: The skill includes shell scripts (scripts/check-urls.sh and scripts/list-urls.sh) and troubleshooting documentation that execute curl and kubectl commands. These commands utilize the disclosed internal endpoints and configuration paths to interact with infrastructure services.
  • [EXTERNAL_DOWNLOADS]: The skill references several external resources, including official Helm repositories for established technology services (e.g., Bitnami, Jetstack, Prometheus) and private Git repositories in Azure DevOps for infrastructure management.
Audit Metadata
Risk Level
MEDIUM
Analyzed
May 13, 2026, 01:13 PM