k8s-security-benchmark

Pass

Audited by Gen Agent Trust Hub on Apr 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's architecture is restricted to read-only analysis of static configuration files provided via the command line. It does not initiate network connections, execute external processes with user-supplied arguments, or interact directly with the Kubernetes API.
  • [CREDENTIALS_UNSAFE]: The file examples/insecure-cluster.json contains a hardcoded fake API key (sk-fake-key-do-not-use). This is a benign placeholder string used specifically within a deliberately misconfigured example to verify the skill's audit check for secrets in environment variables.
  • [SAFE]: The src/checks.py script utilizes dynamic loading for the yaml library to process input files. This implementation is used correctly for handling optional dependencies and invokes yaml.safe_load(), which ensures that the processing of external data does not lead to unsafe deserialization vulnerabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 20, 2026, 01:17 AM
Security Audit — agent-trust-hub — k8s-security-benchmark