k8s-launch-kit-pipeline

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFECREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONPRIVILEGE_ESCALATION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill requires access to the sensitive Kubernetes configuration file located at ~/.kube/config to interact with the cluster. While this is standard for deployment tools, it involves handling sensitive credential paths.
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions for running containerized versions of the deployment tool from the official NVIDIA Container Registry (nvcr.io/nvidia/cloud-native/k8s-launch-kit).
  • [COMMAND_EXECUTION]: The skill generates shell commands for both local and Docker-based execution of the l8k pipeline, which includes hardware discovery and resource deployment.
  • [PRIVILEGE_ESCALATION]: The suggested Docker execution patterns use the --net=host flag, which grants the container full access to the host's network namespace. This high-privilege configuration is necessary for low-level networking fabric discovery but increases the potential impact of a container escape.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it ingests hardware and cluster discovery data which is then used to generate and apply deployment manifests.
  • Ingestion points: The hardware discovery phase (discover) probes the live cluster environment for configuration data.
  • Boundary markers: There are no explicit boundary markers or 'ignore embedded instruction' warnings provided for the ingested discovery data.
  • Capability inventory: The skill has the capability to write YAML manifests to the local file system and apply those resources directly to the Kubernetes cluster via the --deploy flag.
  • Sanitization: No specific sanitization or validation steps for the external hardware discovery data are defined in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 05:22 PM
Security Audit — agent-trust-hub — k8s-launch-kit-pipeline