remediate-k8s-rbac-revoke
Pass
Audited by Gen Agent Trust Hub on Apr 20, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted OCSF 1.8 Detection Findings to identify and revoke Kubernetes RBAC bindings, which creates a surface for indirect prompt injection if the source data is compromised. * Ingestion points:
src/handler.pyreads JSONL records from stdin or file paths. * Boundary markers: Absent; data is parsed as structured JSON. * Capability inventory: Deletion of Kubernetes RoleBindings and ClusterRoleBindings; writing audit evidence to AWS S3 and DynamoDB. * Sanitization: Validates finding producer identity and enforces deny-lists for protected namespaces (e.g., kube-system) and system-prefixed binding names. - [COMMAND_EXECUTION]: Performs administrative resource deletion on a Kubernetes cluster as its primary remediation function. * Evidence:
src/handler.pyuses the official Kubernetes Python client to call delete_namespaced_role_binding and delete_cluster_role_binding. * Context: This behavior is the intended purpose of the skill for responding to privilege escalation alerts. - [DATA_EXFILTRATION]: Transmits audit logs and evidence to external cloud storage and database services. * Evidence:
src/handler.pyuses boto3 to send records to AWS DynamoDB and AWS S3. * Context: These operations target well-known cloud services for required auditing purposes and align with the declared network egress policy.
Audit Metadata