gke-workload-security
Pass
Audited by Gen Agent Trust Hub on May 7, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [SAFE]: The skill provides legitimate security hardening workflows for GKE, including instructions for Workload Identity, Network Policies, and Pod Security Standards.
- [COMMAND_EXECUTION]: The skill executes standard administrative commands using
gcloudandkubectl. A provided bash scriptscripts/audit_cluster.shusesgcloudto describe cluster configurations andjqto parse the results for security auditing purposes. These operations are consistent with the skill's documented intent. - [EXTERNAL_DOWNLOADS]: The manifest
assets/workload-identity-pod.yamlreferences an official Google Cloud SDK container image from the Google Container Registry (gcr.io/google.com/cloudsdktool/cloud-sdk) for verification steps.
Audit Metadata