k8s-network-engineer
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection through the ingestion of cluster diagnostic data and includes instructions that increase agent autonomy by bypassing user confirmation.
- Ingestion points: The
l8k discoverandl8k sosreportworkflows ingest potentially untrusted data from the Kubernetes environment, including cluster configuration metadata, CRDs, and operator logs (SKILL.md). - Boundary markers: The instructions do not specify the use of delimiters or provide warnings to ignore embedded instructions within the collected diagnostic data.
- Capability inventory: The skill grants the agent significant capabilities, including deploying manifests (
l8k deploy), resource cleanup (l8k clean), and direct cluster manipulation viakubectl. - Sanitization: While the agent is instructed to parse JSON output using
jq, there is no requirement to sanitize or filter potential instructions embedded in text-based logs or metadata. - Autonomy abuse: The instructions explicitly direct the agent to use the
--output jsonflag which "auto-confirms" actions, effectively reducing human oversight for deployment and cleanup tasks (SKILL.md).
Audit Metadata