k8s-launch-kit-validate

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the Kubernetes cluster and local file system to perform validation tasks. \n- Ingestion points: Reads Helm release secrets (sh.helm.release.v1.*) from the cluster and YAML manifests from the local deployment directory. \n- Boundary markers: The instructions do not define delimiters or specific warnings to ignore embedded instructions in these external files. \n- Capability inventory: The skill executes the l8k command, performs cluster operations via kubeconfig, and runs network tests using icmp and rping. \n- Sanitization: There is no evidence of content sanitization for the manifests or configuration data processed. \n- [COMMAND_EXECUTION]: The skill invokes the l8k CLI tool and networking utilities through shell execution. \n- Evidence: Uses l8k validate and tools like ping, rping, and ib_write_bw to verify the deployment state. \n- [DATA_EXFILTRATION]: The skill accesses sensitive local configuration files required for cluster interaction. \n- Evidence: Reads the cluster kubeconfig (defaulting to ~/.kube/config) to authenticate and interact with the cluster.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 05:22 PM
Security Audit — agent-trust-hub — k8s-launch-kit-validate