k8s-launch-kit-validate
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the Kubernetes cluster and local file system to perform validation tasks. \n- Ingestion points: Reads Helm release secrets (
sh.helm.release.v1.*) from the cluster and YAML manifests from the local deployment directory. \n- Boundary markers: The instructions do not define delimiters or specific warnings to ignore embedded instructions in these external files. \n- Capability inventory: The skill executes thel8kcommand, performs cluster operations viakubeconfig, and runs network tests usingicmpandrping. \n- Sanitization: There is no evidence of content sanitization for the manifests or configuration data processed. \n- [COMMAND_EXECUTION]: The skill invokes thel8kCLI tool and networking utilities through shell execution. \n- Evidence: Usesl8k validateand tools likeping,rping, andib_write_bwto verify the deployment state. \n- [DATA_EXFILTRATION]: The skill accesses sensitive local configuration files required for cluster interaction. \n- Evidence: Reads the clusterkubeconfig(defaulting to~/.kube/config) to authenticate and interact with the cluster.
Audit Metadata