argocd

Pass

Audited by Gen Agent Trust Hub on Jun 26, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches official ArgoCD installation manifests from the argoproj GitHub organization.
  • [COMMAND_EXECUTION]: Provides numerous CLI command examples for kubectl and argocd to manage cluster resources and application synchronization.
  • [DATA_EXFILTRATION]: Documents the configuration of private Git repositories using SSH keys (referencing standard paths like ~/.ssh/id_rsa) and authentication tokens.
  • [DATA_EXFILTRATION]: Includes instructions for retrieving the initial admin password from Kubernetes secrets and managing declarative secrets for credentials.
  • [PROMPT_INJECTION]: The skill documents GitOps workflows that ingest data from external repositories, creating an indirect prompt injection surface.
  • Ingestion points: External Git repositories configured in Application specs (references/applications.md).
  • Boundary markers: Use of AppProject resources to define source and destination restrictions (references/operations.md).
  • Capability inventory: Ability to deploy arbitrary Kubernetes resources and execute synchronization hooks or jobs (references/sync-options.md).
  • Sanitization: Manifests are processed through Kubernetes API validation and templating engines (Helm/Kustomize).
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 26, 2026, 06:52 PM
Security Audit — agent-trust-hub — argocd