k8s-launch-kit-discover
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFECREDENTIALS_UNSAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill uses the user's Kubernetes configuration file, typically located at
~/.kube/config, to authenticate with the cluster during the discovery process. - [COMMAND_EXECUTION]: The skill executes the
l8k discovercommand-line utility andjqto process and display hardware discovery data. - [PRIVILEGE_ESCALATION]: The discovery workflow creates cluster-scoped
ClusterRoleandClusterRoleBindingresources namedk8s-launch-kit-nic-config-daemonto permit hardware auditing on nodes. These resources are explicitly cleaned up after execution. - [EXTERNAL_DOWNLOADS]: The skill bootstraps a
DaemonSetwhich pulls a discovery image from a repository specified in thel8k-config.yamlconfiguration file. - [INDIRECT_PROMPT_INJECTION]: The skill processes hardware metadata from the cluster, such as PCI device IDs and model names, to generate the
cluster-config.yamlfile. - Ingestion points: Hardware attributes are read from
sysfsvia host pods andNicDeviceCustom Resources as described inreferences/discovery-internals.md. - Boundary markers: The skill does not implement explicit delimiters for hardware-derived strings in the generated YAML output.
- Capability inventory: The skill possesses file system write access and CLI execution capabilities.
- Sanitization: Hardware identifiers are normalized using lowercase mapping, segment filtering, and deterministic hashing for Kubernetes compatibility.
Audit Metadata