Back to skill

Security audit

kubeasz-deploy

Security checks for vulnerabilities and agentic risk

Overview

This Kubernetes deployment skill is mostly coherent documentation, but it includes under-scoped high-impact host and cluster administration steps that users should review carefully before use.

Install only if you are comfortable with an AI-assisted Kubernetes deployment guide that may lead to root SSH setup, cluster-wide RBAC changes, remote installer execution, and destructive cluster operations. Use it first in a disposable lab, require explicit approval before commands run, verify downloaded tools and images, avoid cluster-admin Dashboard tokens, protect or remove deployment SSH keys, and confirm backups and target environments before delete, drain, destroy, or reboot commands.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (6)

T03 · Remote Payload Retrieval and Execution

Error
Location
guides/01-prerequisites.md:578
Finding

Remote Docker Installation Script Is Executed Directly by Bash

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
guides/01-prerequisites.md:425
Finding

Downloaded kubeasz Installer Is Executed Without Integrity Verification

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
guides/03-production-deploy.md:496
Finding

Untrusted Third-Party Container Registry Mirrors Are Recommended for Production Nodes

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
guides/04-post-deploy.md:907
Finding

Kubernetes Dashboard Service Account Is Granted Unrestricted Cluster-Admin Access

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
guides/01-prerequisites.md:281
Finding

Deployment Workflow Establishes Passwordless Root SSH Access with an Unencrypted Private Key

Content
View full analysis
ssh-copy-id root@ ssh-copy-id root@ ``` The bulk-distribution guidance is: ```bash NODE_IPS="192.168.1.1 192.168.1.2 192.168.1.3" for ip in $NODE_IPS; do ssh-copy-id root@$ip done for ip in $NODE_IPS; do ssh root@$ip 'hostname' done ``` ### Technical Analysis Passwordless SSH is operationally relevant to kubeasz and Ansible and is not a covert persistence mechanism. However, the guidance creates an RSA private key with an empty passphrase and authorizes it directly for `root` on every target node. This creates a broad trust relationship from one deployment host to the entire cluster. Compromise of the deployment account or theft of `~/.ssh/id_rsa` immediately becomes root access to all nodes. The guide does not require a dedicated automation identity, constrained sudo permissions, source restrictions in `authorized_keys`, managed key storage, or removal after deployment. ### Attack Path 1. The operator generates the documented private key without a passphrase. 2. The public key is installed in root's `authorized_keys` on every cluster node. 3. An attacker compromises the deployment host, backup, home directory, or account and copies `~/.ssh/id_rsa`. 4. The attacker uses the key to authenticate directly as root on each authorized node. 5. The attacker modifies Kubernetes services, extracts control-plane credentials, or deploys persistent host-level access. ### Impact Assessment Exploitation provides root access to every node on which the key was installed. On control-plane nodes, this includes access to Kubernetes PKI, kubeconfigs, etcd data, se ...[truncated 138 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
guides/04-post-deploy.md:673
Finding

Kubernetes and Registry Secrets Are Passed Through Command-Line Arguments

Content
View full analysis
--from-literal== kubectl create secret tls --cert= --key= kubectl create secret docker-registry \ --docker-server= \ --docker-username= \ --docker-password= kubectl get secret -o yaml ``` ### Technical Analysis The generic secret value and registry password are supplied directly as command-line arguments. Depending on the shell and operating environment, these values may be retained in shell history, terminal transcripts, command auditing, support captures, or process telemetry. During execution, command-line arguments may also be visible to local process-inspection mechanisms. The command that retrieves a Secret as YAML can additionally expose encoded secret material in terminal output or logs. Kubernetes Secret values are base64-encoded rather than encrypted in such output. ### Attack Path 1. An operator replaces the placeholders with a real application secret or registry password. 2. The shell records the command in persistent history, or monitoring and terminal tooling captures it. 3. A local user, administrator, support process, backup reader, or later host attacker retrieves the recorded command. 4. The attacker reuses the exposed credentials against the registry, application, or Kubernetes workload. 5. If Secret YAML is printed, the attacker decodes the base64 values and obtains the underlying credentials. ### Impact Assessment The scope depends on the supplied credential. Exposure may permit unauthorized access to private container registries, application services, TLS private keys, or other protected systems. A registry credential with push rights can also allow image replacement and do ...[truncated 37 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (34)

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · guides/01-prerequisites.md (reported line 558)May include surrounding context.

md
**症状:** SSH 登录仍需输入密码。

**解决:**
- 检查目标节点 `/root/.ssh/authorized_keys` 是否包含公钥
- 检查目标节点 SSH 配置 `PermitRootLogin yes`
- 检查目标节点 `/root/.ssh` 目录权限(700)
- 检查 `authorized_keys` 文件权限(600)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · guides/02-allinone-quickstart.md (reported line 362)May include surrounding context.

md
# 记录 CLUSTER-IP,例如:172.20.1.100

# 在集群内测试
kubectl run test-curl --rm -it --image=curlimages/curl -- curl http://<CLUSTER-IP>/

# 或使用端口转发(本地测试)
kubectl port-forward svc/nginx-svc 8080:80 &

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

文档指导为 Dashboard 创建 cluster-admin 级别的 ClusterRoleBinding,这赋予该账号对整个集群的完全控制权。对于面向初学者的部署指南,这种做法违反最小权限原则;一旦 Token 泄露、被截获或被误分享,攻击者即可接管整个 Kubernetes 集群。

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · guides/01-prerequisites.md (reported line 281)May include surrounding context.

配置SSH免密登录:

bash
# 生成密钥对
ssh-keygen -t rsa -b 2048 -N '' -f ~/.ssh/id_rsa

# 批量分发公钥
for ip in <所有节点IP>; do

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · guides/01-prerequisites.md (reported line 327)May include surrounding context.

配置SSH免密登录:

bash
# 生成密钥对
ssh-keygen -t rsa -b 2048 -N '' -f ~/.ssh/id_rsa

# 批量分发公钥
for ip in <所有节点IP>; do

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · troubleshooting.md (reported line 120)May include surrounding context.

配置SSH免密登录:

bash
# 生成密钥对
ssh-keygen -t rsa -b 2048 -N '' -f ~/.ssh/id_rsa

# 批量分发公钥
for ip in <所有节点IP>; do

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · troubleshooting.md (reported line 124)May include surrounding context.

配置SSH免密登录:

bash
# 生成密钥对
ssh-keygen -t rsa -b 2048 -N '' -f ~/.ssh/id_rsa

# 批量分发公钥
for ip in <所有节点IP>; do

Privileged Kubernetes Workload

High
Category
Tool Misuse
Confidence
91% confidence
Finding

The example PV uses hostPath, which grants pods direct access to a node filesystem path and can undermine isolation if used for general workloads. In a beginner-focused deployment guide, this is more dangerous because readers may copy it into multi-tenant or production environments where hostPath materially increases escape and tampering risk.

Content

Scanner excerpt · troubleshooting.md (reported line 589)May include surrounding context.

  • ReadWriteOnce persistentVolumeReclaimPolicy: Retain storageClassName: standard hostPath: path: /mnt/data
text

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

./ezctl destroy <cluster-name> followed by full redeployment can delete cluster state, workloads, and service availability if run on the wrong environment or without backups. In deployment troubleshooting, this is especially dangerous because operators may execute it under pressure without understanding the blast radius.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly states that the AI will generate or modify configuration files and execute deployment commands, but it does not require explicit user confirmation, preview of changes, or warnings about system-level impact. In a Kubernetes deployment context, these actions can alter host networking, install packages, change cluster state, and affect production infrastructure, so silently performing them is unsafe even if the overall purpose of the skill is legitimate.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document explicitly instructs users to stop and disable host firewalls in test environments without a prominent warning about the resulting exposure. Even in a lab, this can unintentionally expose Kubernetes control-plane and node services to adjacent networks or the internet, increasing attack surface and making later compromise easier.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documented command docker system prune -a can remove all unused images and other Docker resources, which may delete assets the user still needs and disrupt unrelated workloads on the host. Presenting it as routine cleanup without an explicit destructive-data warning raises the risk of accidental operational damage.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · guides/02-allinone-quickstart.md (reported line 362)May include surrounding context.

md
# 记录 CLUSTER-IP,例如:172.20.1.100

# 在集群内测试
kubectl run test-curl --rm -it --image=curlimages/curl -- curl http://<CLUSTER-IP>/

# 或使用端口转发(本地测试)
kubectl port-forward svc/nginx-svc 8080:80 &

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document instructs users to destroy the cluster and reboot the node as part of troubleshooting, but it does not clearly warn that these actions are destructive and can remove workloads, configuration, and local state. In an operational context, a reader may copy-paste these commands on the wrong system or without backups, causing avoidable downtime and data loss.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The cleanup section includes full cluster destruction and node reboot steps without prominent warnings about irreversible effects, service interruption, and possible loss of locally stored application data. Because this is a quickstart guide aimed at beginners, the missing safety framing increases the chance of accidental misuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The guide instructs operators to set up passwordless SSH to every node and then use that trust path for automated administration, but it does not warn about key theft, root-level lateral movement, host authenticity verification, or scope minimization. In a production Kubernetes deployment context, broadly distributed SSH trust materially increases blast radius if the deployment host or private key is compromised.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document provides commands to drain and delete worker and master nodes from the cluster. Although it says '谨慎操作' for master removal, it does not clearly warn about service interruption, pod eviction, loss of local ephemeral data, and the need to verify backups and cluster quorum before proceeding.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Manifest 描述强调为初学者提供 Kubernetes 集群部署指导,以及 AllinOne/高可用部署支持;而本节不仅是部署后验证,还系统性教授创建、更新、删除资源,节点 drain/delete,命名空间删除,以及资源配额配置等持续运维操作。这些内容属于通用集群管理与运维范畴,明显超出“部署指导”这一宣称范围。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The documentation tells users to delete a namespace and notes that it will remove all resources in it, and elsewhere includes broad deletion commands such as deleting all resources in a namespace. Because these operations can remove user workloads and data, the markdown should provide a more explicit warning about irreversibility and scope before presenting them as general-use commands.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Manifest 声明的核心目的是帮助初学者部署 Kubernetes 集群,而本节进一步指导安装 Ingress、Prometheus/Grafana、NFS Provisioner、Dashboard、Harbor 和日志系统。这些属于平台扩展与附加基础设施集成,不是完成集群部署本身所必需的验证或最小化指导,导致描述与实际内容范围不一致。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

这里不仅授予了 cluster-admin 权限,而且没有明确警告其安全后果,容易让初学者把高危配置视为标准步骤。缺少风险提示会显著提高误部署概率,使高权限 Dashboard 账户长期存在并暴露在不必要的访问面前。

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · guides/01-prerequisites.md (reported line 370)May include surrounding context.

md
# 启动服务
systemctl start chronyd
systemctl enable chronyd

# 验证
chronyc sources

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · guides/01-prerequisites.md (reported line 390)May include surrounding context.

md
# 启动服务
systemctl start chronyd
systemctl enable chronyd

# 验证
chronyc sources

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · guides/01-prerequisites.md (reported line 461)May include surrounding context.

md
# 启动服务
systemctl start chronyd
systemctl enable chronyd

# 验证
chronyc sources

Static analysis

No suspicious patterns detected.