remediate-container-escape-k8s
Warn
Audited by Gen Agent Trust Hub on Apr 20, 2026
Risk Level: MEDIUMDATA_EXFILTRATIONDATA_EXFILTRATIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [DATA_EXPOSURE]: The forensic collector accesses sensitive host-level information by reading from
/procand/var/logvia host-mounted directories. This allows the collection of process metadata, memory maps, and container logs directly from the underlying node. - [COMMAND_EXECUTION]: The skill mutates cluster state by applying
NetworkPolicyobjects to isolate workloads and creatingVolumeSnapshotobjects for forensic preservation. These actions are gated behind a human approval model and require specific environment variables (incident ID and approver) to be set. - [DATA_EXFILTRATION]: Collected forensic bundles and audit logs are transmitted to external AWS services (S3 and DynamoDB). While these are intended destinations for incident evidence, the process involves transferring sensitive system data to remote storage.
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by ingesting OCSF findings from external sources (stdin/files). A malicious finding could attempt to redirect remediation actions toward sensitive workloads. This risk is addressed via producer-locking and a deny-list of protected namespaces.
- [DYNAMIC_EXECUTION]: The forensic collector dynamically loads internal modules using
importlib.util. While the loading is restricted to local files, it utilizes dynamic execution patterns to assemble functionality at runtime.
Audit Metadata