remediate-container-escape-k8s

Warn

Audited by Gen Agent Trust Hub on Apr 20, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONDATA_EXFILTRATIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [DATA_EXPOSURE]: The forensic collector accesses sensitive host-level information by reading from /proc and /var/log via host-mounted directories. This allows the collection of process metadata, memory maps, and container logs directly from the underlying node.
  • [COMMAND_EXECUTION]: The skill mutates cluster state by applying NetworkPolicy objects to isolate workloads and creating VolumeSnapshot objects for forensic preservation. These actions are gated behind a human approval model and require specific environment variables (incident ID and approver) to be set.
  • [DATA_EXFILTRATION]: Collected forensic bundles and audit logs are transmitted to external AWS services (S3 and DynamoDB). While these are intended destinations for incident evidence, the process involves transferring sensitive system data to remote storage.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by ingesting OCSF findings from external sources (stdin/files). A malicious finding could attempt to redirect remediation actions toward sensitive workloads. This risk is addressed via producer-locking and a deny-list of protected namespaces.
  • [DYNAMIC_EXECUTION]: The forensic collector dynamically loads internal modules using importlib.util. While the loading is restricted to local files, it utilizes dynamic execution patterns to assemble functionality at runtime.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 20, 2026, 01:17 AM
Security Audit — agent-trust-hub — remediate-container-escape-k8s