kubespray-operations
Pass
Audited by Gen Agent Trust Hub on Feb 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill describes using
ansible-playbookwith root escalation (--become),kubectl, andetcdctlfor critical cluster tasks. These actions are standard for the intended administrative role. - [EXTERNAL_DOWNLOADS]: It references procedures for updating Kubespray via
gitand installing dependencies viapip, which are standard workflows for maintaining the tool. - [PROMPT_INJECTION]: The skill interacts with external configuration files and system command outputs, representing a potential surface for indirect prompt injection. No malicious patterns were identified.
- Ingestion points:
inventory.iniandkubectloutput. - Boundary markers: Not present in the instruction set.
- Capability inventory: Full cluster administrative access via playbooks and etcd certificate access.
- Sanitization: Relies on toolchain integrity.
Audit Metadata