GKE Autopilot Hardening

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward external API wrapper for generating GKE hardening configuration, with a privacy documentation gap around request identifiers but no evidence of hidden execution or unsafe local behavior.

Install only if you intend to use the referenced external hardening API. Prefer pseudonymous session IDs, avoid sending real user IDs or sensitive operational data unless the provider is approved for your environment, and review generated manifests before applying them to a GKE cluster.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The request schema collects sessionId and optional userId/timestamp fields without documenting purpose, minimization, retention, or privacy handling. In a security-focused skill, opaque collection of identifiers increases the risk of unnecessary tracking, accidental logging of sensitive metadata, and privacy noncompliance if callers send user-linked values by default.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal