app-service-log-analysis

Pass

Audited by Gen Agent Trust Hub on Oct 9, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill generates and executes shell commands using kubectl and the aws CLI to discover resources, manage configurations, and stream logs. This includes starting background processes for real-time monitoring.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and analyzes application logs and experiment reports from external sources. While this creates a surface for indirect prompt injection, the instructions focus on pattern matching (e.g., error counting, recovery signal detection) rather than executing log content. The skill lacks explicit sanitization but the risk is inherent to the log analysis use case.
  • [DATA_EXFILTRATION]: The skill performs a deep scan of Kubernetes clusters, including environment variables, ConfigMaps, and Secret metadata (key names). While this accesses configuration data, the instructions explicitly forbid decoding secret values and the data is used locally to map service dependencies for the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 9, 2026, 08:52 AM