k8s
Pass
Audited by Gen Agent Trust Hub on Mar 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions for executing system commands for Kubernetes cluster management and GitOps operations using
kubectlandflux.- [DATA_EXFILTRATION]: The instructions direct the agent to access sensitive Kubernetes configuration files located at~/.kube/*.yaml. These files contain authentication tokens and cluster certificates. Additionally, the skill interacts with internal service endpoints on thetomnowak.workdomain.- [REMOTE_CODE_EXECUTION]: The skill describes patterns for executing remote commands within cluster containers viakubectl execcombined with network operations likewget.- [PROMPT_INJECTION]: The skill exhibits vulnerability to indirect prompt injection. 1. Ingestion points: The agent is instructed to read untrusted data from the cluster usingkubectl logs,kubectl describe, andkubectl get events. 2. Boundary markers: No boundary markers or instructions to ignore embedded content are provided. 3. Capability inventory: The skill provides high-privilege access viakubectlandfluxcommands. 4. Sanitization: There is no evidence of sanitization or filtering applied to the data retrieved from the cluster API.
Audit Metadata