skills/tinh2/skills-hub-registry/k8s/Gen Agent Trust Hub

k8s

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect prompt injection surface identified in the application analysis phase.
  • Ingestion points: The skill scans project files, including Dockerfiles and application source code, to extract metadata like ports and environment variables (Phase 1).
  • Boundary markers: Absent. There are no instructions for the agent to treat the contents of project files as untrusted data or to use protective delimiters.
  • Capability inventory: The agent has permissions to write files to the local system and execute commands such as kubectl dry-run or docker build --check for validation (Phase 8).
  • Sanitization: Absent. Configuration metadata extracted from the project files is used to populate manifest templates without explicit sanitization steps.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 10:58 AM
Security Audit — agent-trust-hub — k8s