k8s-launch-kit-dryrun
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides templates for the agent to execute the
l8kCLI tool for generating Kubernetes manifests and performing dry-run cluster operations. - [DATA_EXFILTRATION]: The skill references the sensitive credential file path
~/.kube/configto facilitate communication with Kubernetes clusters. This is a standard requirement for the tool's primary purpose. - [INDIRECT_PROMPT_INJECTION]:
- Ingestion points: Untrusted data enters the agent context through the
--user-configflag, which points to external YAML/configuration files. - Boundary markers: No delimiters or instructions are present to ensure the agent ignores potential instructions embedded within the configuration files.
- Capability inventory: The skill allows the execution of the
l8kcommand-line tool and file system writes to a specified output directory. - Sanitization: There are no explicit sanitization or validation routines defined for the external configuration data before it is processed by the agent.
Audit Metadata