kubernetes-specialist
Fail
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: CRITICALREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill provides instructions to download and execute shell scripts directly from external URLs. Evidence includes commands piping curl output to sh or bash in references/service-mesh.md and references/multi-cluster.md.- [EXTERNAL_DOWNLOADS]: The skill directs the agent to download binaries and Kubernetes manifests from external sources. Additionally, automated security scans identified the skill's primary documentation domain (jeffallan.github.io) as blacklisted and flagged the SKILL.md file for poor reputation. Evidence: SKILL.md, references/gitops.md, references/multi-cluster.md.- [COMMAND_EXECUTION]: The skill documentation includes administrative commands for system-level modifications and container interaction, such as moving binaries to protected paths using sudo and accessing container shells via kubectl exec. Evidence: references/multi-cluster.md, references/troubleshooting.md.- [PRIVILEGE_ESCALATION]: The skill provides patterns for deploying Kubernetes workloads with high-privilege settings, including securityContext configurations for privileged: true and allowPrivilegeEscalation: true. Evidence: references/storage.md, SKILL.md.- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and apply data from untrusted external sources like Git repositories (via ArgoCD or Flux) and remote manifest URLs. Ingestion points: GitRepository and Application manifests. Boundary markers: Absent in provided YAML examples. Capability inventory: Subprocess execution via kubectl for manifest deployment and container debugging. Sanitization: Not implemented in provided templates.
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
- AI detected serious security threats
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata