detect-container-escape-k8s
Pass
Audited by Gen Agent Trust Hub on Apr 20, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted Kubernetes audit events and interpolates external data (e.g., actor names, resource names) into detection findings. This creates a surface for indirect prompt injection if a downstream AI agent processes these findings without sanitization.\n
- Ingestion points: Audit log data is read in
src/detect.pyfrom standard input or a user-provided file path.\n - Boundary markers: No explicit delimiters or instructions are used in the output to warn downstream systems to ignore embedded commands.\n
- Capability inventory: The skill performs data parsing and string interpolation but has no access to sensitive capabilities such as network operations, subprocess execution, or arbitrary file system writes.\n
- Sanitization: External input from audit logs is used directly in finding descriptions without validation or escaping.
Audit Metadata