skills/mukul975/anthropic-cybersecurity-skills/performing-kubernetes-cis-benchmark-with-kube-bench/Gen Agent Trust Hub
performing-kubernetes-cis-benchmark-with-kube-bench
Pass
Audited by Gen Agent Trust Hub on Apr 9, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The
scripts/agent.pyandscripts/process.pyutilities executekube-benchandkubectlcommands to collect cluster configuration data. These operations are performed with predefined arguments or restricted user inputs, aligning with the skill's auditing purpose.\n- [EXTERNAL_DOWNLOADS]: The documentation provides instructions to download thekube-benchbinary and Kubernetes manifests from Aqua Security's official GitHub repository. These sources are well-known and standard for the described security task.\n- [COMMAND_EXECUTION]: The skill includes Kubernetes manifest examples that require host-level permissions (e.g.,hostPID: true) to audit the control plane and worker nodes. This privilege level is necessary forkube-benchto perform its intended security checks.
Audit Metadata