k8s-launch-kit-deploy

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes shell-based commands for l8k and kubectl to facilitate the deployment and verification of networking resources within a Kubernetes environment.
  • [CREDENTIALS_UNSAFE]: The skill references sensitive configuration files and credentials, including ~/.kube/config and Kubernetes imagePullSecrets, which are required to authenticate with clusters and private container registries. This access is consistent with the skill's stated purpose for cluster deployment and management.
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect injection as it processes external configuration and manifest data.
  • Ingestion points: Deployment manifests located in the directory specified by --deployment-files and configuration profiles in values.yaml (SKILL.md).
  • Boundary markers: No specific delimiters or safety instructions are defined to separate ingested data from agent instructions.
  • Capability inventory: The skill executes shell commands for manifest application and interacts with the Helm SDK for chart management (SKILL.md).
  • Sanitization: The skill relies on the validation mechanisms inherent in the l8k and kubectl binaries.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 05:22 PM
Security Audit — agent-trust-hub — k8s-launch-kit-deploy