kubernetes-deployment
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill recommends the use of the
helm-diffplugin, referencing its community GitHub repository (https://github.com/databus23/helm-diff), as a recommended practice for safe deployments. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted data provided by the user, specifically Kubernetes YAML manifests and diagnostic log outputs. This creates a potential attack surface for indirect instructions hidden within the technical data.
- Ingestion points: User-provided manifests and diagnostic logs referenced in the troubleshooting guides (e.g.,
references/sharp_edges.md). - Boundary markers: Not present; the instructions do not define specific delimiters or "ignore instructions" markers for the untrusted diagnostic data.
- Capability inventory: The skill uses standard agent capabilities including file access and potential shell command execution for cluster management.
- Sanitization: No explicit sanitization or filtering of user-provided manifest content is specified.
Audit Metadata