k8s-launch-kit-pipeline
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFECREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONPRIVILEGE_ESCALATION
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill requires access to the sensitive Kubernetes configuration file located at
~/.kube/configto interact with the cluster. While this is standard for deployment tools, it involves handling sensitive credential paths. - [EXTERNAL_DOWNLOADS]: The skill provides instructions for running containerized versions of the deployment tool from the official NVIDIA Container Registry (
nvcr.io/nvidia/cloud-native/k8s-launch-kit). - [COMMAND_EXECUTION]: The skill generates shell commands for both local and Docker-based execution of the
l8kpipeline, which includes hardware discovery and resource deployment. - [PRIVILEGE_ESCALATION]: The suggested Docker execution patterns use the
--net=hostflag, which grants the container full access to the host's network namespace. This high-privilege configuration is necessary for low-level networking fabric discovery but increases the potential impact of a container escape. - [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it ingests hardware and cluster discovery data which is then used to generate and apply deployment manifests.
- Ingestion points: The hardware discovery phase (
discover) probes the live cluster environment for configuration data. - Boundary markers: There are no explicit boundary markers or 'ignore embedded instruction' warnings provided for the ingested discovery data.
- Capability inventory: The skill has the capability to write YAML manifests to the local file system and apply those resources directly to the Kubernetes cluster via the
--deployflag. - Sanitization: No specific sanitization or validation steps for the external hardware discovery data are defined in the instructions.
Audit Metadata