operating-kubernetes
Warn
Audited by Snyk on Feb 15, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The skill includes commands and instructions that fetch and install manifests and charts from public third-party sources (e.g., kubectl apply -f https://github.com/kubernetes-sigs/metrics-server/releases/latest/download/components.yaml and helm repo add https://prometheus-community.github.io/helm-charts), so it clearly ingests untrusted, user-hosted web content that the agent/operator would read or execute as part of the workflow.
Audit Metadata