talos-os-expert

Fail

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches the talosctl installation script from the official talos.dev domain within a GitHub Actions workflow example in SKILL.md.
  • [EXTERNAL_DOWNLOADS]: Downloads various Kubernetes manifests and CNI configurations from well-known repositories including Sidero Labs, Cilium, Flannel, and Calico in installation-guide.md and security-hardening.md.
  • [REMOTE_CODE_EXECUTION]: Provides a standard installation pattern for the talosctl CLI using a shell script piped from the project's official domain.
  • [COMMAND_EXECUTION]: Provides extensive patterns for cluster management, node bootstrapping, and maintenance using talosctl and kubectl.
  • [INDIRECT_PROMPT_INJECTION]: The skill represents an attack surface for indirect prompt injection through the ingestion of external YAML configuration files. 1. Ingestion points: Processes Talos machine configurations (controlplane.yaml, worker.yaml) using talosctl validate and yq in SKILL.md. 2. Boundary markers: No explicit delimiters or warnings are used when reading configuration data. 3. Capability inventory: The skill utilizes powerful CLI tools (talosctl, kubectl) capable of cluster-wide modifications and node-level system changes. 4. Sanitization: Validation is limited to schema checks via talosctl validate.
Recommendations
  • HIGH: Downloads and executes remote code from: https://talos.dev/install - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 16, 2026, 03:03 PM
Security Audit — agent-trust-hub — talos-os-expert