k8s-security-benchmark
Pass
Audited by Gen Agent Trust Hub on Apr 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's architecture is restricted to read-only analysis of static configuration files provided via the command line. It does not initiate network connections, execute external processes with user-supplied arguments, or interact directly with the Kubernetes API.
- [CREDENTIALS_UNSAFE]: The file
examples/insecure-cluster.jsoncontains a hardcoded fake API key (sk-fake-key-do-not-use). This is a benign placeholder string used specifically within a deliberately misconfigured example to verify the skill's audit check for secrets in environment variables. - [SAFE]: The
src/checks.pyscript utilizes dynamic loading for theyamllibrary to process input files. This implementation is used correctly for handling optional dependencies and invokesyaml.safe_load(), which ensures that the processing of external data does not lead to unsafe deserialization vulnerabilities.
Audit Metadata