deploy-self-hosted
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill describes standard deployment workflows for the Scalekit platform using Helm and Kubernetes Gateway API.
- [EXTERNAL_DOWNLOADS]: The instructions involve downloading a configuration script (setup-secrets.sh) from the vendor's documentation site and applying manifests from the vendor's distribution portal, which are standard operational steps for the product.
- [COMMAND_EXECUTION]: The skill uses standard administrative tools such as kubectl, helm, openssl, and python3 for cluster management, configuration verification, and local secret generation.
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection via external portal commands. 1. Ingestion points: Step 3 in SKILL.md (portal connect command) and references/production-deployment.md (manifest URL). 2. Boundary markers: Absent for portal-supplied manifest URLs and interactive script inputs. 3. Capability inventory: kubectl apply and bash script execution are used for infrastructure setup. 4. Sanitization: None observed in the provided instructions, as it relies on vendor-provided distribution channels.
Audit Metadata