detect-privilege-escalation-k8s
Pass
Audited by Gen Agent Trust Hub on Apr 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements deterministic detection logic for Kubernetes audit logs using standard Python libraries. Analysis of the source code (
src/detect.py) confirms it performs structured data processing without any hidden or malicious behaviors. - [COMMAND_EXECUTION]: The skill provides a legitimate command-line interface for security analysts to process JSONL logs. It does not invoke arbitrary shell commands or utilize unsafe functions like
eval()oros.system(). - [EXTERNAL_DOWNLOADS]: All external URLs referenced in the documentation point to trusted security industry resources, including MITRE ATT&CK, NIST, and the OCSF project.
- [DATA_EXFILTRATION]: No network activity or unauthorized data transmission patterns were found. The skill operates entirely on local input provided by the user through standard I/O or file paths.
Audit Metadata