detect-container-escape-k8s

Pass

Audited by Gen Agent Trust Hub on Apr 20, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted Kubernetes audit events and interpolates external data (e.g., actor names, resource names) into detection findings. This creates a surface for indirect prompt injection if a downstream AI agent processes these findings without sanitization.\n
  • Ingestion points: Audit log data is read in src/detect.py from standard input or a user-provided file path.\n
  • Boundary markers: No explicit delimiters or instructions are used in the output to warn downstream systems to ignore embedded commands.\n
  • Capability inventory: The skill performs data parsing and string interpolation but has no access to sensitive capabilities such as network operations, subprocess execution, or arbitrary file system writes.\n
  • Sanitization: External input from audit logs is used directly in finding descriptions without validation or escaping.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 20, 2026, 01:18 AM
Security Audit — agent-trust-hub — detect-container-escape-k8s