eks-workload-best-practice-assessment

Pass

Audited by Gen Agent Trust Hub on Oct 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from two main sources: configuration output from the Kubernetes cluster (kubectl get ... -o json) and search results from external documentation providers (context7 and aws-knowledge-mcp-server). This data is processed to generate assessments, which could allow malicious instructions embedded in the cluster state or the documentation to influence the agent's behavior.
  • Ingestion points: Workload configurations (Deployments, Pods, RBAC) collected via kubectl and documentation content fetched from external search tools.
  • Capability inventory: The skill has the ability to execute shell commands (kubectl, aws CLI) and write to the local filesystem using specific tools.
  • Boundary markers: There are no explicit instructions to the agent to treat external content as data only or to ignore embedded instructions within that data.
  • Sanitization: No sanitization or filtering of the ingested configuration or documentation data is described before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 9, 2026, 08:49 AM