k8s
Pass
Audited by Gen Agent Trust Hub on Apr 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to perform privileged system operations including kernel module loading using 'sudo modprobe' and service management via 'sudo systemctl' within the Colima VM environment.- [COMMAND_EXECUTION]: Extensive use of 'ssh' for port forwarding and remote command execution on the cluster host, which is required for managing the virtualized infrastructure nodes.- [EXTERNAL_DOWNLOADS]: Fetches Kubernetes manifests from well-known sources such as the Rancher GitHub repository and installs official Helm charts for services like LiveKit and Bluesky PDS.- [REMOTE_CODE_EXECUTION]: Describes an architecture for an 'Agent Runner' that dynamically executes code pulled from external repositories within sandboxed Kubernetes Jobs, using environment variables for task configuration.- [CREDENTIALS_UNSAFE]: Accesses sensitive local configuration and authentication files including '
/.kube/config' and '/.talos/config' to facilitate cluster management tasks.
Audit Metadata