azure-kubernetes-automatic-readiness
Pass
Audited by Gen Agent Trust Hub on Jun 27, 2026
Risk Level: SAFE
Full Analysis
- Indirect Prompt Injection Surface: The skill evaluates external Kubernetes manifests (processed in
SKILL.mdunder Offline Mode), which creates a potential entry point for indirect instructions. This is mitigated by a mandatory human-in-the-loop requirement where users must explicitly review and approve all suggested YAML changes before they are applied. - Official Tool Integration: The skill integrates with the
mcp_azure_mcp_akstool for cluster discovery and assessment. All network interactions and documentation references (e.g.,aka.ms/azure-mcp-setup) point to official Microsoft resources and operate within expected vendor boundaries. - Sensitive Data Protection: A core guardrail (Guardrail 2) explicitly instructs the agent to never transmit or display sensitive information such as secrets, connection strings, or service account tokens, ensuring data privacy during the assessment.
- Administrative Boundary Controls: The skill is strictly limited to a read-only assessment role. It includes explicit instructions to avoid modifying cluster state or running commands like
kubectl applywithout direct user confirmation of generated diffs.
Audit Metadata