k8s-launch-kit-deploy
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes shell-based commands for
l8kandkubectlto facilitate the deployment and verification of networking resources within a Kubernetes environment. - [CREDENTIALS_UNSAFE]: The skill references sensitive configuration files and credentials, including
~/.kube/configand KubernetesimagePullSecrets, which are required to authenticate with clusters and private container registries. This access is consistent with the skill's stated purpose for cluster deployment and management. - [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect injection as it processes external configuration and manifest data.
- Ingestion points: Deployment manifests located in the directory specified by
--deployment-filesand configuration profiles invalues.yaml(SKILL.md). - Boundary markers: No specific delimiters or safety instructions are defined to separate ingested data from agent instructions.
- Capability inventory: The skill executes shell commands for manifest application and interacts with the Helm SDK for chart management (SKILL.md).
- Sanitization: The skill relies on the validation mechanisms inherent in the
l8kandkubectlbinaries.
Audit Metadata