talos-os-expert
Fail
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches the talosctl installation script from the official talos.dev domain within a GitHub Actions workflow example in SKILL.md.
- [EXTERNAL_DOWNLOADS]: Downloads various Kubernetes manifests and CNI configurations from well-known repositories including Sidero Labs, Cilium, Flannel, and Calico in installation-guide.md and security-hardening.md.
- [REMOTE_CODE_EXECUTION]: Provides a standard installation pattern for the talosctl CLI using a shell script piped from the project's official domain.
- [COMMAND_EXECUTION]: Provides extensive patterns for cluster management, node bootstrapping, and maintenance using talosctl and kubectl.
- [INDIRECT_PROMPT_INJECTION]: The skill represents an attack surface for indirect prompt injection through the ingestion of external YAML configuration files. 1. Ingestion points: Processes Talos machine configurations (controlplane.yaml, worker.yaml) using talosctl validate and yq in SKILL.md. 2. Boundary markers: No explicit delimiters or warnings are used when reading configuration data. 3. Capability inventory: The skill utilizes powerful CLI tools (talosctl, kubectl) capable of cluster-wide modifications and node-level system changes. 4. Sanitization: Validation is limited to schema checks via talosctl validate.
Recommendations
- HIGH: Downloads and executes remote code from: https://talos.dev/install - DO NOT USE without thorough review
Audit Metadata