kubernetes-specialist
Pass
Audited by Gen Agent Trust Hub on Aug 23, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides installation commands for common Kubernetes ecosystem tools including ArgoCD, Flux, and clusterctl. These resources are fetched from official GitHub organizations (argoproj, kubernetes-sigs, fluxcd) and well-known project domains.\n- [REMOTE_CODE_EXECUTION]: Documentation includes standard installation methods for Istio and Submariner that involve piping remote scripts to a shell (curl | sh). These patterns are limited to official installation procedures for highly reputable infrastructure tools.\n- [COMMAND_EXECUTION]: The troubleshooting and reference guides include various
kubectland shell commands for managing and inspecting cluster resources. These are expected administrative functions for the declared specialist role.\n- [PROMPT_INJECTION]: The skill processes user-provided workload requirements to generate manifests. It mitigates potential injection risks by providing explicit constraints (MUST NOT DO) and comprehensive Best Practices sections that mandate security isolation and warn against unsafe configurations.\n- [SAFE]: Documentation examples for Kubernetes Secrets contain dummy strings and placeholder credentials (e.g., 'sk-1234567890abcdef', 'MySecurePassword123!'). These are clearly marked as patterns for educational reference and do not leak sensitive information.
Audit Metadata