k8s-launch-kit-shared
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides explicit instructions for the agent to execute shell commands, such as using
which l8kto verify the tool's installation and invoking variousl8ksubcommands to perform cluster operations. - [PRIVILEGE_ESCALATION]: The installation instructions for the tool involve the use of
sudoto copy binaries and configuration templates into system-protected directories like/usr/local/binand/usr/local/share. - [EXTERNAL_DOWNLOADS]: The
l8k preset updatecommand allows for the retrieval of updated hardware topology presets from an external repository on GitHub. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data inputs, including cluster hardware metadata and user-supplied YAML configuration files, which represent an attack surface for indirect prompt injection if the inputs are derived from untrusted sources.
- Ingestion points: Cluster discovery data via
l8k discoverand configuration files via the--user-configflag. - Boundary markers: The skill documentation does not define specific delimiters for separating data from instructions in configuration files.
- Capability inventory: The skill facilitates file system writes during manifest generation, network communication for cluster discovery, and deployment of Kubernetes resources.
- Sanitization: The skill relies on the underlying
l8kbinary's internal logic for validating and sanitizing configuration data before processing.
Audit Metadata