kubernetes-health

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external Kubernetes APIs, which may contain attacker-controlled content in metadata or status fields.
  • Ingestion points: The scripts/discover_apis.py script and the kubectl commands defined in references/operator-checks.md read state directly from the cluster.
  • Boundary markers: The diagnostic scripts produce structured JSON output, providing clear boundaries for the agent.
  • Capability inventory: The skill uses Bash to run kubectl and uv to execute Python scripts.
  • Sanitization: The scripts do not perform explicit validation or sanitization of string-based metadata (e.g., event logs or resource names) before inclusion in the diagnostic report.
  • [COMMAND_EXECUTION]: The skill invokes system commands to interact with the cluster and run diagnostic logic.
  • Evidence: SKILL.md provides instructions for running kubectl commands and executing scripts via uv run.
  • [EXTERNAL_DOWNLOADS]: The skill downloads the kubernetes Python library to facilitate cluster discovery.
  • Evidence: scripts/discover_apis.py specifies kubernetes>=28.1.0 as a dependency. This is an official and widely trusted package for Kubernetes integration.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 02:42 PM
Security Audit — agent-trust-hub — kubernetes-health