auditing-kubernetes-rbac-privilege-escalation

Pass

Audited by Gen Agent Trust Hub on Aug 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: Fetches the rbac-police binary from Palo Alto Networks' official GitHub repository and executes it to analyze Kubernetes privilege escalation paths.
  • [EXTERNAL_DOWNLOADS]: Installs several standard Kubernetes security plugins (who-can, access-matrix, rbac-lookup) using the kubectl krew package manager.
  • [COMMAND_EXECUTION]: Employs a Python wrapper (scripts/agent.py) to invoke kubectl commands, such as auth can-i, to systematically inventory and audit permissions across the cluster.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 23, 2026, 05:53 PM
Security Audit — agent-trust-hub — auditing-kubernetes-rbac-privilege-escalation