kubernetes-specialist
Warn
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: MEDIUMCREDENTIALS_UNSAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill includes multiple hardcoded dummy credentials within example manifests for ConfigMaps and Secrets. While these are intended for illustrative purposes, their use of literal strings matching specific patterns (such as sk- prefixes) can trigger security alerts.\n
- Evidence: Hardcoded dummy API key 'sk-1234567890abcdef', 'MySecurePassword123!', and 'super-secret-password' in references/configuration.md\n
- Evidence: Base64 encoded credentials ('bXl1c2VyOm15cGFzc3dvcmQ=') in Docker registry secret examples in references/configuration.md\n- [COMMAND_EXECUTION]: The documentation provides instructions for performing high-privilege operations that can be used for privilege escalation, including accessing the underlying node's filesystem and running containers with host network and PID access.\n
- Evidence: Troubleshooting command 'kubectl debug node/node-01 ... -- chroot /host' allowing access to the host filesystem in references/troubleshooting.md\n
- Evidence: DaemonSet workload configuration using hostNetwork and hostPID privileges in references/workloads.md\n- [EXTERNAL_DOWNLOADS]: The skill provides instructions to download and apply configuration files from well-known cloud-native software providers and organizations.\n
- Evidence: Fetches ArgoCD installation manifests and Sealed Secrets controller configuration from official project repositories in references/gitops.md\n- [REMOTE_CODE_EXECUTION]: The skill includes instructions to download and execute setup scripts directly from well-known infrastructure tool providers.\n
- Evidence: Fetches and executes installation scripts for Istio and Linkerd service meshes in references/service-mesh.md\n
- Evidence: Fetches and executes the Submariner deployment script in references/multi-cluster.md
Audit Metadata