kubespray-helm-airgap

Pass

Audited by Gen Agent Trust Hub on Feb 28, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to download the helm-push plugin from the ChartMuseum GitHub repository.
  • [EXTERNAL_DOWNLOADS]: The skill references pulling container images from well-known registries including GitHub Container Registry (ghcr.io) and Docker Hub (docker.io).
  • [COMMAND_EXECUTION]: The documentation includes commands to modify system-level configuration in /etc/containers/registries.conf to allow insecure (non-TLS) communication with local registries, which is a common requirement in isolated laboratory or air-gapped environments.
  • [COMMAND_EXECUTION]: The skill suggests setting broad file permissions (chmod 777) on the local data directory used by the ChartMuseum service to ensure the container process has write access.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 28, 2026, 04:44 AM