detect-sensitive-secret-read-k8s
Pass
Audited by Gen Agent Trust Hub on Apr 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill operates as a stateless data processor that reads Kubernetes audit logs (in OCSF or native format) from standard input or a local file and outputs detection findings to standard output.
- [DATA_EXPOSURE_AND_EXFILTRATION]: No evidence of credential exposure or unauthorized data exfiltration. The skill does not perform any network operations; it only writes detection records to standard output or a user-specified output file.
- [REMOTE_CODE_EXECUTION]: No remote code execution patterns or external package dependencies were found. The implementation relies exclusively on Python standard libraries (argparse, fnmatch, hashlib, json, sys, datetime, typing).
- [INDIRECT_PROMPT_INJECTION]: While the skill processes untrusted Kubernetes audit log data, it does so through a stateless pattern-matching logic that lacks exploitable capabilities like shell execution or file system writes. Data is sanitized through JSON parsing and strict type casting to strings and integers.
- [DYNAMIC_CONTEXT_INJECTION]: No use of the dynamic context injection syntax was detected in the skill metadata or instructions.
Audit Metadata