istio-expert

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill provides instructions to download and execute the Istio installation script directly from the official website using curl -L https://istio.io/downloadIstio | sh - within the reference documentation.
  • [EXTERNAL_DOWNLOADS]: Fetches configuration and installation scripts from official Istio project domains and references dashboards and proxies from established community sites such as kiali.io and envoyproxy.io.
  • [COMMAND_EXECUTION]: The skill utilizes administrative commands via kubectl and istioctl to manage service mesh components, sidecar proxies, and cluster networking policies.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes Kubernetes manifests and service mesh configurations which, if sourced from untrusted inputs, could lead to indirect prompt injection.
  • Ingestion points: Reads cluster state and resource definitions via kubectl and istioctl commands (found in references/CORE_CONCEPTS.md).
  • Boundary markers: No explicit boundary markers or 'ignore' instructions are used when presenting retrieved configuration data to the agent.
  • Capability inventory: The skill has Bash access for executing kubectl and istioctl commands, along with file system Read, Write, and Edit permissions (defined in SKILL.md).
  • Sanitization: Relies on default platform and tool-level validation; no additional sanitization of ingested data is performed by the skill itself.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 06:42 PM
Security Audit — agent-trust-hub — istio-expert