k8s-security-policies

Pass

Audited by Gen Agent Trust Hub on May 12, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill provides legitimate guidance for securing Kubernetes clusters. The templates follow security best practices, such as Template 6 in assets/network-policy-template.yaml which explicitly blocks access to the cloud metadata service IP (169.254.169.254) to prevent credential theft.
  • [NO_CODE]: The skill does not contain any executable scripts (e.g., Python, JavaScript, or shell scripts). It consists entirely of documentation and static YAML configuration templates.
  • [COMMAND_EXECUTION]: troubleshooting sections in SKILL.md and references/rbac-patterns.md describe the use of standard kubectl diagnostic commands. These commands (e.g., kubectl auth can-i) are used to verify permissions and are appropriate for the intended purpose of cluster security auditing.
Audit Metadata
Risk Level
SAFE
Analyzed
May 12, 2026, 06:52 AM
Security Audit — agent-trust-hub — k8s-security-policies