manage-kubernetes-secrets
Warn
Audited by Gen Agent Trust Hub on Feb 27, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches deployment manifests and binary tools from GitHub repositories of well-known organizations including Bitnami Labs, cert-manager, and Stakater.
- [REMOTE_CODE_EXECUTION]: Employs
kubectl apply -fwith remote URLs to install infrastructure components, which executes the remote YAML content within the cluster context. - [COMMAND_EXECUTION]: Utilizes
sudofor administrative installation of thekubesealbinary to system-protected paths. - [COMMAND_EXECUTION]: Executes complex command sequences using
kubectl,helm,aws,gcloud, andazto manage encryption providers and cloud identities. - [COMMAND_EXECUTION]: Generates and executes a local shell script for database credential rotation.
Audit Metadata