Back to skill

Security audit

K8s Ops Fix

Security checks for vulnerabilities and agentic risk

Overview

This Kubernetes operations skill is openly about cluster administration, but its docs and wrapper grant or allow very broad authority with weak scoping.

Review before installing. Use only a least-privileged kubeconfig or ServiceAccount, preferably in a non-production cluster first. Do not follow the cluster-admin binding guidance unless you intentionally want full cluster control. Pin and inspect any remote Kubernetes manifests before applying them, avoid plaintext SSH passwords, and require clear per-tool input validation before trusting this for production operations.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
guides/01-installation.md:112
Finding

Documentation Grants Unrestricted Kubernetes Cluster-Administrator Privileges

Content
View full analysis
kubectl create rolebinding admin-binding \ --clusterrole=admin \ --user= \ --namespace= ``` ### Technical Analysis The installation guide binds the plugin ServiceAccount directly to Kubernetes' built-in `cluster-admin` ClusterRole. The troubleshooting guide similarly recommends granting `cluster-admin` to a user whenever an authorization failure occurs. The `cluster-admin` role provides unrestricted access to every Kubernetes API resource and non-resource endpoint. This is substantially broader than the permissions normally required for workload inspection and routine namespace-level operations. It also contradicts the least-privilege recommendations in `SKILL.md`. Because the plugin exposes tools for command execution, workload mutation, namespace management, security inspection, and SSH monitoring, unnecessarily granting it cluster-administrator privileges enlarges the impact of any compromised dependency, unsafe tool call, or attacker-controlled Agent input. ### Attack Path 1. An administrator follows the installation or troubleshooting instructions. 2. The plugin ServiceAccount or user receives the `cluster-admin` role. 3. An attacker compromises the Agent session, supplies a malicious tool request, or exploits behavior in the unavai ...[truncated 841 chars]
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Warning
Location
guides/03-advanced-usage.md:197
Finding

Mutable Remote Kubernetes Manifest Is Applied Directly to the Cluster

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/index.ts:8
Finding

Privileged Tool Handlers Accept Arbitrary Unvalidated Parameters

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (47)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 21)May include surrounding context.

md
## 系统要求

- kubectl 命令行工具
- 有效的 kubeconfig 文件
- Kubernetes 集群访问权限

## 安装 kubectl

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

md
## 系统要求

- kubectl 命令行工具
- 有效的 kubeconfig 文件
- Kubernetes 集群访问权限

## 安装 kubectl

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

md
## 系统要求

- kubectl 命令行工具
- 有效的 kubeconfig 文件
- Kubernetes 集群访问权限

## 安装 kubectl

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

md
## 系统要求

- kubectl 命令行工具
- 有效的 kubeconfig 文件
- Kubernetes 集群访问权限

## 安装 kubectl

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

md
## 系统要求

- kubectl 命令行工具
- 有效的 kubeconfig 文件
- Kubernetes 集群访问权限

## 安装 kubectl

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 61)May include surrounding context.

md
## 系统要求

- kubectl 命令行工具
- 有效的 kubeconfig 文件
- Kubernetes 集群访问权限

## 安装 kubectl

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · guides/01-installation.md (reported line 6)May include surrounding context.

md
## 系统要求

- kubectl 命令行工具
- 有效的 kubeconfig 文件
- Kubernetes 集群访问权限

## 安装 kubectl

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · guides/01-installation.md (reported line 49)May include surrounding context.

md
## 系统要求

- kubectl 命令行工具
- 有效的 kubeconfig 文件
- Kubernetes 集群访问权限

## 安装 kubectl

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · guides/01-installation.md (reported line 55)May include surrounding context.

md
## 系统要求

- kubectl 命令行工具
- 有效的 kubeconfig 文件
- Kubernetes 集群访问权限

## 安装 kubectl

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · guides/01-installation.md (reported line 70)May include surrounding context.

md
## 系统要求

- kubectl 命令行工具
- 有效的 kubeconfig 文件
- Kubernetes 集群访问权限

## 安装 kubectl

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · guides/01-installation.md (reported line 71)May include surrounding context.

md
## 系统要求

- kubectl 命令行工具
- 有效的 kubeconfig 文件
- Kubernetes 集群访问权限

## 安装 kubectl

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · openclaw.plugin.json (reported line 7)May include surrounding context.

json
## 系统要求

- kubectl 命令行工具
- 有效的 kubeconfig 文件
- Kubernetes 集群访问权限

## 安装 kubectl

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · openclaw.plugin.json (reported line 9)May include surrounding context.

json
## 系统要求

- kubectl 命令行工具
- 有效的 kubeconfig 文件
- Kubernetes 集群访问权限

## 安装 kubectl

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · troubleshooting.md (reported line 23)May include surrounding context.

md
## 系统要求

- kubectl 命令行工具
- 有效的 kubeconfig 文件
- Kubernetes 集群访问权限

## 安装 kubectl

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · troubleshooting.md (reported line 29)May include surrounding context.

md
## 系统要求

- kubectl 命令行工具
- 有效的 kubeconfig 文件
- Kubernetes 集群访问权限

## 安装 kubectl

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · troubleshooting.md (reported line 32)May include surrounding context.

md
## 系统要求

- kubectl 命令行工具
- 有效的 kubeconfig 文件
- Kubernetes 集群访问权限

## 安装 kubectl

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · troubleshooting.md (reported line 33)May include surrounding context.

md
## 系统要求

- kubectl 命令行工具
- 有效的 kubeconfig 文件
- Kubernetes 集群访问权限

## 安装 kubectl

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · troubleshooting.md (reported line 37)May include surrounding context.

md
## 系统要求

- kubectl 命令行工具
- 有效的 kubeconfig 文件
- Kubernetes 集群访问权限

## 安装 kubectl

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · guides/01-installation.md (reported line 33)May include surrounding context.

md
# 或使用包管理器
# Ubuntu/Debian
sudo apt-get update && sudo apt-get install -y kubectl

# CentOS/RHEL
sudo yum install -y kubectl

Credential Access

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

md
"properties": {
      "kubeconfigPath": {
        "type": "string",
        "description": "Custom path to kubeconfig file (defaults to ~/.kube/config)"
      },
      "defaultContext": {
        "type": "string",

Credential Access

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · guides/01-installation.md (reported line 71)May include surrounding context.

md
"properties": {
      "kubeconfigPath": {
        "type": "string",
        "description": "Custom path to kubeconfig file (defaults to ~/.kube/config)"
      },
      "defaultContext": {
        "type": "string",

Credential Access

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · guides/01-installation.md (reported line 74)May include surrounding context.

md
"properties": {
      "kubeconfigPath": {
        "type": "string",
        "description": "Custom path to kubeconfig file (defaults to ~/.kube/config)"
      },
      "defaultContext": {
        "type": "string",

Credential Access

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · openclaw.plugin.json (reported line 9)May include surrounding context.

json
"properties": {
      "kubeconfigPath": {
        "type": "string",
        "description": "Custom path to kubeconfig file (defaults to ~/.kube/config)"
      },
      "defaultContext": {
        "type": "string",

Credential Access

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · troubleshooting.md (reported line 37)May include surrounding context.

md
"properties": {
      "kubeconfigPath": {
        "type": "string",
        "description": "Custom path to kubeconfig file (defaults to ~/.kube/config)"
      },
      "defaultContext": {
        "type": "string",

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · troubleshooting.md (reported line 33)May include surrounding context.

md
kubectl config view

# 设置正确的 kubeconfig
export KUBECONFIG=/path/to/your/kubeconfig

# 或使用默认路径
mkdir -p ~/.kube

Static analysis

No suspicious patterns detected.