eg-enterprise
Pass
Audited by Gen Agent Trust Hub on Apr 27, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches the Envoy Gateway Helm chart from the official Envoy Proxy repository on Docker Hub (oci://docker.io/envoyproxy/gateway-helm and oci://docker.io/envoyproxy/gateway-crds-helm).
- [COMMAND_EXECUTION]: Provides instructions for installing the gateway and verifying the setup using standard CLI tools like helm and kubectl.
- [PROMPT_INJECTION]: The skill ingests user input through an intake interview to populate Kubernetes manifests. This creates an indirect prompt injection surface where maliciously crafted user input could potentially alter the generated configuration or shell commands.
- Ingestion points: Intake interview questions in SKILL.md.
- Boundary markers: None identified for user input interpolation.
- Capability inventory: Deployment of K8s resources via helm and kubectl in SKILL.md.
- Sanitization: No explicit sanitization or validation of interview answers is specified.
Audit Metadata