cloud-k8s
Pass
Audited by Gen Agent Trust Hub on Jul 18, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to process output from external security scanners (e.g., Trivy, Nuclei) and Kubernetes management tools (kubectl) that interact with untrusted container images, manifests, and cluster resources. The instructions lack explicit isolation logic or boundary markers for this external data, creating an attack surface for indirect prompt injection.\n
- Ingestion points: Command outputs from Trivy, Nuclei, and kubectl as referenced in SKILL.md.\n
- Boundary markers: Absent; the skill does not define delimiters or specific 'ignore' instructions for data processed by these tools.\n
- Capability inventory: The skill utilizes command execution for cloud resource enumeration and cluster auditing (SKILL.md).\n
- Sanitization: No sanitization, validation, or escaping of tool-generated content is defined in the instructions.\n- [EXTERNAL_DOWNLOADS]: The skill refers to bootstrapping well-known security utilities including Trivy, Nmap, and Nuclei (SKILL.md). These are standard technology tools for security auditing and are referenced within their intended context.
Audit Metadata