T03 · Remote Payload Retrieval and Execution
- Location
skills/kubeblocks-install/SKILL.md:70- Finding
Unverified Remote Helm Installer Executed Directly by Bash
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a coherent KubeBlocks database-management skill, but it gives an agent broad Kubernetes control and includes risky automatic installer and uninstall commands that need review before use.
Install this only if you want an agent to manage Kubernetes-hosted databases. Use a least-privilege kubeconfig scoped to the intended cluster and namespace, review and pin any downloaded installers, require explicit approval before sudo, kubectl apply/delete, password retrieval, external exposure, uninstall, or production changes, and test first outside production.
skills/kubeblocks-install/SKILL.md:70Unverified Remote Helm Installer Executed Directly by Bash
skills/kubeblocks-create-local-k8s-cluster/SKILL.md:96Unverified Remote k3d Installer Executed from a Mutable Branch
skills/kubeblocks-install/SKILL.md:49kubectl Binary Installed with Elevated Privileges Without Integrity Verification
skills/kubeblocks-create-local-k8s-cluster/SKILL.md:60Kind Executable Installed Without Published Checksum Verification
skills/kubeblocks-create-local-k8s-cluster/SKILL.md:78Mutable Minikube Package Installed with sudo Without Integrity Verification
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
- helm
optional_tools:
- npx
notes: Requires access to a Kubernetes cluster (kubeconfig). For local development, the skill can create a cluster using Kind, Minikube, or k3d.
---
# KubeBlocks — Databases on Kubernetes, Made Simple
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
- helm
optional_tools:
- npx
notes: Requires access to a Kubernetes cluster (kubeconfig). For local development, the skill can create a cluster using Kind, Minikube, or k3d.
---
# KubeBlocks — Databases on Kubernetes, Made Simple
This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.
| `volumeClaimTemplates` | []VolumeClaimTemplate | No | Persistent volume claims for this component. |
| `serviceAccountName` | string | No | Custom ServiceAccount for the component pods. |
| `services` | []Service | No | Component-level service overrides. |
| `systemAccounts` | []SystemAccount | No | Override system account credentials. |
| `schedulingPolicy` | SchedulingPolicy | No | Component-level scheduling constraints. |
| `configs` | []ConfigTemplate | No | Custom configuration template overrides. |
Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.
brew install kind
# Linux (amd64)
[ $(uname -m) = x86_64 ] && curl -Lo ./kind https://kind.sigs.k8s.io/dl/v0.24.0/kind-linux-amd64
chmod +x ./kind && sudo mv ./kind /usr/local/bin/kind
# Linux (arm64)
Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.
# Linux (amd64)
[ $(uname -m) = x86_64 ] && curl -Lo ./kind https://kind.sigs.k8s.io/dl/v0.24.0/kind-linux-amd64
chmod +x ./kind && sudo mv ./kind /usr/local/bin/kind
# Linux (arm64)
[ $(uname -m) = aarch64 ] && curl -Lo ./kind https://kind.sigs.k8s.io/dl/v0.24.0/kind-linux-arm64
Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.
# Linux (amd64)
[ $(uname -m) = x86_64 ] && curl -Lo ./kind https://kind.sigs.k8s.io/dl/v0.24.0/kind-linux-amd64
chmod +x ./kind && sudo mv ./kind /usr/local/bin/kind
# Linux (arm64)
[ $(uname -m) = aarch64 ] && curl -Lo ./kind https://kind.sigs.k8s.io/dl/v0.24.0/kind-linux-arm64
Piping a remote script directly into bash executes network-fetched code immediately with no opportunity for inspection, pinning, or integrity verification. Even in a developer setup skill, this is a high-risk pattern because compromise of the source, transport, or repo content can lead to arbitrary code execution on the host.
brew install k3d
# Linux
curl -s https://raw.githubusercontent.com/k3d-io/k3d/main/install.sh | bash
# Windows
choco install k3d
This chained command downloads a binary, marks it executable, and immediately installs it with sudo in one flow. Chaining reduces review opportunities and increases the chance an agent executes a risky privileged installation without validation or user awareness.
# Linux (amd64)
curl -LO "https://dl.k8s.io/release/$(curl -L -s https://dl.k8s.io/release/stable.txt)/bin/linux/amd64/kubectl"
chmod +x kubectl && sudo mv kubectl /usr/local/bin/
# Linux (arm64)
curl -LO "https://dl.k8s.io/release/$(curl -L -s https://dl.k8s.io/release/stable.txt)/bin/linux/arm64/kubectl"
The arm64 command has the same chaining problem, combining download, permission change, and privileged install in a compact sequence. This pattern is dangerous in autonomous or semi-autonomous execution because it compresses multiple trust boundaries into one action.
curl -LO "https://dl.k8s.io/release/$(curl -L -s https://dl.k8s.io/release/stable.txt)/bin/linux/arm64/kubectl" chmod +x kubectl && sudo mv kubectl /usr/local/bin/
### 1b: Helm (v3+)
Piping a remotely fetched script directly into bash executes unaudited code immediately from the network. In an agent skill, this is especially dangerous because it enables arbitrary code execution on the host with little visibility or control.
brew install helm
curl https://raw.githubusercontent.com/helm/helm/main/scripts/get-helm-3 | bash
### 1c: Verify cluster access
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
If this fails, the user has no accessible Kubernetes cluster. **Stop here** and tell the user:
- For local testing, use the [create-local-k8s-cluster](../kubeblocks-create-local-k8s-cluster/SKILL.md) skill
- For production, ensure kubeconfig is properly configured (`~/.kube/config` or `$KUBECONFIG`)
**Resource requirements** (minimum):
- Control Plane: 1 node, 4 cores, 4GB RAM, 50GB storage
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
If this fails, the user has no accessible Kubernetes cluster. **Stop here** and tell the user:
- For local testing, use the [create-local-k8s-cluster](../kubeblocks-create-local-k8s-cluster/SKILL.md) skill
- For production, ensure kubeconfig is properly configured (`~/.kube/config` or `$KUBECONFIG`)
**Resource requirements** (minimum):
- Control Plane: 1 node, 4 cores, 4GB RAM, 50GB storage
The uninstall section includes irreversible destructive commands such as deleting all clusters across namespaces and removing CRDs, but does not present a strong warning or require confirmation. In an agent-operated workflow, this creates a high risk of accidental data loss and service disruption.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
```bash
kubectl apply -f custom-password-secret.yaml
2. Reference in Cluster CR systemAccounts:
The trigger text is overly broad: phrases like 'I need a database' or generic mentions of MySQL can cause this skill to activate even when the user did not ask for Kubernetes or KubeBlocks specifically. That can misroute requests, leading the agent to make inappropriate infrastructure assumptions, produce unsafe provisioning guidance, or bypass a more suitable skill with narrower scope.
The README states the agent will use these skills automatically whenever a database is needed, with little indication of confirmation gates or scope limits. In this context, the skill can lead an agent into provisioning or modifying Kubernetes-hosted database infrastructure based on broad prompts, increasing the chance of unintended high-impact actions.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
| Skill | Description |
|-------|-------------|
| [kubeblocks](./SKILL.md) | Entry point for all database tasks. Routes to the right skill based on user intent. |
| [kubeblocks-create-local-k8s-cluster](./skills/kubeblocks-create-local-k8s-cluster/SKILL.md) | Create a local Kubernetes test cluster using Kind, Minikube, or k3d. |
| [kubeblocks-install](./skills/kubeblocks-install/SKILL.md) | Install the KubeBlocks operator. Handles version selection, network detection, registry configuration. |
| [kubeblocks-manage-addons](./skills/kubeblocks-manage-addons/SKILL.md) | Install, uninstall, and upgrade database engine addons. |
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
| Skill | Description |
|-------|-------------|
| [kubeblocks](./SKILL.md) | Entry point for all database tasks. Routes to the right skill based on user intent. |
| [kubeblocks-create-local-k8s-cluster](./skills/kubeblocks-create-local-k8s-cluster/SKILL.md) | Create a local Kubernetes test cluster using Kind, Minikube, or k3d. |
| [kubeblocks-install](./skills/kubeblocks-install/SKILL.md) | Install the KubeBlocks operator. Handles version selection, network detection, registry configuration. |
| [kubeblocks-manage-addons](./skills/kubeblocks-manage-addons/SKILL.md) | Install, uninstall, and upgrade database engine addons. |
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
| Skill | Description |
|-------|-------------|
| [kubeblocks](./SKILL.md) | Entry point for all database tasks. Routes to the right skill based on user intent. |
| [kubeblocks-create-local-k8s-cluster](./skills/kubeblocks-create-local-k8s-cluster/SKILL.md) | Create a local Kubernetes test cluster using Kind, Minikube, or k3d. |
| [kubeblocks-install](./skills/kubeblocks-install/SKILL.md) | Install the KubeBlocks operator. Handles version selection, network detection, registry configuration. |
| [kubeblocks-manage-addons](./skills/kubeblocks-manage-addons/SKILL.md) | Install, uninstall, and upgrade database engine addons. |
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
|-------|-------------|
| [kubeblocks](./SKILL.md) | Entry point for all database tasks. Routes to the right skill based on user intent. |
| [kubeblocks-create-local-k8s-cluster](./skills/kubeblocks-create-local-k8s-cluster/SKILL.md) | Create a local Kubernetes test cluster using Kind, Minikube, or k3d. |
| [kubeblocks-install](./skills/kubeblocks-install/SKILL.md) | Install the KubeBlocks operator. Handles version selection, network detection, registry configuration. |
| [kubeblocks-manage-addons](./skills/kubeblocks-manage-addons/SKILL.md) | Install, uninstall, and upgrade database engine addons. |
### Cluster Provisioning & Deletion
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
|-------|-------------|
| [kubeblocks](./SKILL.md) | Entry point for all database tasks. Routes to the right skill based on user intent. |
| [kubeblocks-create-local-k8s-cluster](./skills/kubeblocks-create-local-k8s-cluster/SKILL.md) | Create a local Kubernetes test cluster using Kind, Minikube, or k3d. |
| [kubeblocks-install](./skills/kubeblocks-install/SKILL.md) | Install the KubeBlocks operator. Handles version selection, network detection, registry configuration. |
| [kubeblocks-manage-addons](./skills/kubeblocks-manage-addons/SKILL.md) | Install, uninstall, and upgrade database engine addons. |
### Cluster Provisioning & Deletion
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
|-------|-------------|
| [kubeblocks](./SKILL.md) | Entry point for all database tasks. Routes to the right skill based on user intent. |
| [kubeblocks-create-local-k8s-cluster](./skills/kubeblocks-create-local-k8s-cluster/SKILL.md) | Create a local Kubernetes test cluster using Kind, Minikube, or k3d. |
| [kubeblocks-install](./skills/kubeblocks-install/SKILL.md) | Install the KubeBlocks operator. Handles version selection, network detection, registry configuration. |
| [kubeblocks-manage-addons](./skills/kubeblocks-manage-addons/SKILL.md) | Install, uninstall, and upgrade database engine addons. |
### Cluster Provisioning & Deletion
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
| [kubeblocks](./SKILL.md) | Entry point for all database tasks. Routes to the right skill based on user intent. |
| [kubeblocks-create-local-k8s-cluster](./skills/kubeblocks-create-local-k8s-cluster/SKILL.md) | Create a local Kubernetes test cluster using Kind, Minikube, or k3d. |
| [kubeblocks-install](./skills/kubeblocks-install/SKILL.md) | Install the KubeBlocks operator. Handles version selection, network detection, registry configuration. |
| [kubeblocks-manage-addons](./skills/kubeblocks-manage-addons/SKILL.md) | Install, uninstall, and upgrade database engine addons. |
### Cluster Provisioning & Deletion
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
| [kubeblocks](./SKILL.md) | Entry point for all database tasks. Routes to the right skill based on user intent. |
| [kubeblocks-create-local-k8s-cluster](./skills/kubeblocks-create-local-k8s-cluster/SKILL.md) | Create a local Kubernetes test cluster using Kind, Minikube, or k3d. |
| [kubeblocks-install](./skills/kubeblocks-install/SKILL.md) | Install the KubeBlocks operator. Handles version selection, network detection, registry configuration. |
| [kubeblocks-manage-addons](./skills/kubeblocks-manage-addons/SKILL.md) | Install, uninstall, and upgrade database engine addons. |
### Cluster Provisioning & Deletion
The README advertises destructive and operationally sensitive capabilities such as deletion, scaling, switchover, restore, upgrades, and external exposure without prominent warnings about downtime, data loss, credential rotation, or public network exposure. Because this skill targets production-grade databases on Kubernetes, missing warnings materially raise the risk of unsafe agent actions in real infrastructure.
No suspicious patterns detected.