k8s-launch-kit-shared

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides explicit instructions for the agent to execute shell commands, such as using which l8k to verify the tool's installation and invoking various l8k subcommands to perform cluster operations.
  • [PRIVILEGE_ESCALATION]: The installation instructions for the tool involve the use of sudo to copy binaries and configuration templates into system-protected directories like /usr/local/bin and /usr/local/share.
  • [EXTERNAL_DOWNLOADS]: The l8k preset update command allows for the retrieval of updated hardware topology presets from an external repository on GitHub.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data inputs, including cluster hardware metadata and user-supplied YAML configuration files, which represent an attack surface for indirect prompt injection if the inputs are derived from untrusted sources.
  • Ingestion points: Cluster discovery data via l8k discover and configuration files via the --user-config flag.
  • Boundary markers: The skill documentation does not define specific delimiters for separating data from instructions in configuration files.
  • Capability inventory: The skill facilitates file system writes during manifest generation, network communication for cluster discovery, and deployment of Kubernetes resources.
  • Sanitization: The skill relies on the underlying l8k binary's internal logic for validating and sanitizing configuration data before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 05:22 PM
Security Audit — agent-trust-hub — k8s-launch-kit-shared