kubernetes-health
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external Kubernetes APIs, which may contain attacker-controlled content in metadata or status fields.
- Ingestion points: The
scripts/discover_apis.pyscript and thekubectlcommands defined inreferences/operator-checks.mdread state directly from the cluster. - Boundary markers: The diagnostic scripts produce structured JSON output, providing clear boundaries for the agent.
- Capability inventory: The skill uses
Bashto runkubectlanduvto execute Python scripts. - Sanitization: The scripts do not perform explicit validation or sanitization of string-based metadata (e.g., event logs or resource names) before inclusion in the diagnostic report.
- [COMMAND_EXECUTION]: The skill invokes system commands to interact with the cluster and run diagnostic logic.
- Evidence:
SKILL.mdprovides instructions for runningkubectlcommands and executing scripts viauv run. - [EXTERNAL_DOWNLOADS]: The skill downloads the
kubernetesPython library to facilitate cluster discovery. - Evidence:
scripts/discover_apis.pyspecifieskubernetes>=28.1.0as a dependency. This is an official and widely trusted package for Kubernetes integration.
Audit Metadata