k8s-launch-kit-generate
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied configuration files (
cluster-config.yaml) and network topology data (topology.json) to generate Kubernetes manifests. This ingestion of untrusted data represents an indirect prompt injection surface. - Ingestion points: The skill instructions specify using the
--user-configand--topology-fileflags to ingest external YAML and JSON files into thel8kprocessing workflow (as described in SKILL.md). - Boundary markers: There are no explicit instructions for the agent to use boundary markers or to ignore potential instructions embedded within the ingested configuration files.
- Capability inventory: The skill utilizes the
l8kCLI tool to perform manifest generation and file writing operations. It also supports JSON output mode, which the agent is expected to read to process further (as described in the Example section of SKILL.md). - Sanitization: The instructions do not define sanitization or validation steps for the content of the external configuration or topology files before they are processed by the CLI tool.
Audit Metadata