kubernetes
Pass
Audited by Gen Agent Trust Hub on Jun 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill implements tools for executing arbitrary commands through the
kubectlbinary, specifically via therawandexecfunctions inskill.js. Therawtool allows for the construction of unconstrained command strings, while theexectool permits running commands directly within containerized environments. These features provide the agent with significant administrative control over the cluster. - [CREDENTIALS_UNSAFE]: The
configtool provides anaction=viewparameter that retrieves and displays the content of the active kubeconfig. This configuration file contains sensitive information, including cluster API endpoints, client certificates, and authentication tokens required for cluster access. - [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface by processing untrusted data from the cluster environment.
- Ingestion points: The skill retrieves pod logs and resource descriptions (metadata and specifications) from the cluster via the
logs,get, anddescribetools defined inskill.js. - Boundary markers: Data returned from cluster operations is not enclosed in protective delimiters or accompanied by instructions for the agent to ignore embedded commands.
- Capability inventory: The skill possesses capabilities to modify cluster state using the
apply,create, anddeletetools, and to execute code in pods via theexectool. - Sanitization: Content fetched from the cluster, such as log output or resource specifications, is passed to the agent without validation or escaping, potentially allowing malicious content within those fields to influence agent behavior.
Audit Metadata