Back to skill

Security audit

Kubeblocks

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent KubeBlocks database-management skill, but it gives an agent broad Kubernetes control and includes risky automatic installer and uninstall commands that need review before use.

Install this only if you want an agent to manage Kubernetes-hosted databases. Use a least-privilege kubeconfig scoped to the intended cluster and namespace, review and pin any downloaded installers, require explicit approval before sudo, kubectl apply/delete, password retrieval, external exposure, uninstall, or production changes, and test first outside production.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (5)

T03 · Remote Payload Retrieval and Execution

Error
Location
skills/kubeblocks-install/SKILL.md:70
Finding

Unverified Remote Helm Installer Executed Directly by Bash

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
skills/kubeblocks-create-local-k8s-cluster/SKILL.md:96
Finding

Unverified Remote k3d Installer Executed from a Mutable Branch

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
skills/kubeblocks-install/SKILL.md:49
Finding

kubectl Binary Installed with Elevated Privileges Without Integrity Verification

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
skills/kubeblocks-create-local-k8s-cluster/SKILL.md:60
Finding

Kind Executable Installed Without Published Checksum Verification

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
skills/kubeblocks-create-local-k8s-cluster/SKILL.md:78
Finding

Mutable Minikube Package Installed with sudo Without Integrity Verification

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (144)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 11)May include surrounding context.

md
- helm
  optional_tools:
    - npx
  notes: Requires access to a Kubernetes cluster (kubeconfig). For local development, the skill can create a cluster using Kind, Minikube, or k3d.
---

# KubeBlocks — Databases on Kubernetes, Made Simple

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skills/kubeblocks-install/SKILL.md (reported line 81)May include surrounding context.

md
- helm
  optional_tools:
    - npx
  notes: Requires access to a Kubernetes cluster (kubeconfig). For local development, the skill can create a cluster using Kind, Minikube, or k3d.
---

# KubeBlocks — Databases on Kubernetes, Made Simple

Instruction Override

High
Category
Prompt Injection
Confidence
90% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · skills/kubeblocks-create-cluster/references/reference.md (reported line 41)May include surrounding context.

md
| `volumeClaimTemplates` | []VolumeClaimTemplate | No | Persistent volume claims for this component. |
| `serviceAccountName` | string | No | Custom ServiceAccount for the component pods. |
| `services` | []Service | No | Component-level service overrides. |
| `systemAccounts` | []SystemAccount | No | Override system account credentials. |
| `schedulingPolicy` | SchedulingPolicy | No | Component-level scheduling constraints. |
| `configs` | []ConfigTemplate | No | Custom configuration template overrides. |

Chaining Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · skills/kubeblocks-create-local-k8s-cluster/SKILL.md (reported line 60)May include surrounding context.

md
brew install kind

# Linux (amd64)
[ $(uname -m) = x86_64 ] && curl -Lo ./kind https://kind.sigs.k8s.io/dl/v0.24.0/kind-linux-amd64
chmod +x ./kind && sudo mv ./kind /usr/local/bin/kind

# Linux (arm64)

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · skills/kubeblocks-create-local-k8s-cluster/SKILL.md (reported line 61)May include surrounding context.

md
# Linux (amd64)
[ $(uname -m) = x86_64 ] && curl -Lo ./kind https://kind.sigs.k8s.io/dl/v0.24.0/kind-linux-amd64
chmod +x ./kind && sudo mv ./kind /usr/local/bin/kind

# Linux (arm64)
[ $(uname -m) = aarch64 ] && curl -Lo ./kind https://kind.sigs.k8s.io/dl/v0.24.0/kind-linux-arm64

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · skills/kubeblocks-create-local-k8s-cluster/SKILL.md (reported line 65)May include surrounding context.

md
# Linux (amd64)
[ $(uname -m) = x86_64 ] && curl -Lo ./kind https://kind.sigs.k8s.io/dl/v0.24.0/kind-linux-amd64
chmod +x ./kind && sudo mv ./kind /usr/local/bin/kind

# Linux (arm64)
[ $(uname -m) = aarch64 ] && curl -Lo ./kind https://kind.sigs.k8s.io/dl/v0.24.0/kind-linux-arm64

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

Piping a remote script directly into bash executes network-fetched code immediately with no opportunity for inspection, pinning, or integrity verification. Even in a developer setup skill, this is a high-risk pattern because compromise of the source, transport, or repo content can lead to arbitrary code execution on the host.

Content

Scanner excerpt · skills/kubeblocks-create-local-k8s-cluster/SKILL.md (reported line 96)May include surrounding context.

md
brew install k3d

# Linux
curl -s https://raw.githubusercontent.com/k3d-io/k3d/main/install.sh | bash

# Windows
choco install k3d

Chaining Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

This chained command downloads a binary, marks it executable, and immediately installs it with sudo in one flow. Chaining reduces review opportunities and increases the chance an agent executes a risky privileged installation without validation or user awareness.

Content

Scanner excerpt · skills/kubeblocks-install/SKILL.md (reported line 50)May include surrounding context.

md
# Linux (amd64)
curl -LO "https://dl.k8s.io/release/$(curl -L -s https://dl.k8s.io/release/stable.txt)/bin/linux/amd64/kubectl"
chmod +x kubectl && sudo mv kubectl /usr/local/bin/

# Linux (arm64)
curl -LO "https://dl.k8s.io/release/$(curl -L -s https://dl.k8s.io/release/stable.txt)/bin/linux/arm64/kubectl"

Chaining Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

The arm64 command has the same chaining problem, combining download, permission change, and privileged install in a compact sequence. This pattern is dangerous in autonomous or semi-autonomous execution because it compresses multiple trust boundaries into one action.

Content

Scanner excerpt · skills/kubeblocks-install/SKILL.md (reported line 54)May include surrounding context.

Linux (arm64)

curl -LO "https://dl.k8s.io/release/$(curl -L -s https://dl.k8s.io/release/stable.txt)/bin/linux/arm64/kubectl" chmod +x kubectl && sudo mv kubectl /usr/local/bin/

text

### 1b: Helm (v3+)

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

Piping a remotely fetched script directly into bash executes unaudited code immediately from the network. In an agent skill, this is especially dangerous because it enables arbitrary code execution on the host with little visibility or control.

Content

Scanner excerpt · skills/kubeblocks-install/SKILL.md (reported line 70)May include surrounding context.

brew install helm

Linux (script, works on amd64/arm64)

curl https://raw.githubusercontent.com/helm/helm/main/scripts/get-helm-3 | bash

text

### 1c: Verify cluster access

Credential Access

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skills/kubeblocks-install/SKILL.md (reported line 81)May include surrounding context.

md
If this fails, the user has no accessible Kubernetes cluster. **Stop here** and tell the user:
- For local testing, use the [create-local-k8s-cluster](../kubeblocks-create-local-k8s-cluster/SKILL.md) skill
- For production, ensure kubeconfig is properly configured (`~/.kube/config` or `$KUBECONFIG`)

**Resource requirements** (minimum):
- Control Plane: 1 node, 4 cores, 4GB RAM, 50GB storage

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skills/kubeblocks-install/SKILL.md (reported line 81)May include surrounding context.

md
If this fails, the user has no accessible Kubernetes cluster. **Stop here** and tell the user:
- For local testing, use the [create-local-k8s-cluster](../kubeblocks-create-local-k8s-cluster/SKILL.md) skill
- For production, ensure kubeconfig is properly configured (`~/.kube/config` or `$KUBECONFIG`)

**Resource requirements** (minimum):
- Control Plane: 1 node, 4 cores, 4GB RAM, 50GB storage

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The uninstall section includes irreversible destructive commands such as deleting all clusters across namespaces and removing CRDs, but does not present a strong warning or require confirmation. In an agent-operated workflow, this creates a high risk of accidental data loss and service disruption.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skills/kubeblocks-manage-accounts/SKILL.md (reported line 93)May include surrounding context.

text

```bash
kubectl apply -f custom-password-secret.yaml

2. Reference in Cluster CR systemAccounts:

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger text is overly broad: phrases like 'I need a database' or generic mentions of MySQL can cause this skill to activate even when the user did not ask for Kubernetes or KubeBlocks specifically. That can misroute requests, leading the agent to make inappropriate infrastructure assumptions, produce unsafe provisioning guidance, or bypass a more suitable skill with narrower scope.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README states the agent will use these skills automatically whenever a database is needed, with little indication of confirmation gates or scope limits. In this context, the skill can lead an agent into provisioning or modifying Kubernetes-hosted database infrastructure based on broad prompts, increasing the chance of unintended high-impact actions.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 20)May include surrounding context.

md
| Skill | Description |
|-------|-------------|
| [kubeblocks](./SKILL.md) | Entry point for all database tasks. Routes to the right skill based on user intent. |
| [kubeblocks-create-local-k8s-cluster](./skills/kubeblocks-create-local-k8s-cluster/SKILL.md) | Create a local Kubernetes test cluster using Kind, Minikube, or k3d. |
| [kubeblocks-install](./skills/kubeblocks-install/SKILL.md) | Install the KubeBlocks operator. Handles version selection, network detection, registry configuration. |
| [kubeblocks-manage-addons](./skills/kubeblocks-manage-addons/SKILL.md) | Install, uninstall, and upgrade database engine addons. |

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

md
| Skill | Description |
|-------|-------------|
| [kubeblocks](./SKILL.md) | Entry point for all database tasks. Routes to the right skill based on user intent. |
| [kubeblocks-create-local-k8s-cluster](./skills/kubeblocks-create-local-k8s-cluster/SKILL.md) | Create a local Kubernetes test cluster using Kind, Minikube, or k3d. |
| [kubeblocks-install](./skills/kubeblocks-install/SKILL.md) | Install the KubeBlocks operator. Handles version selection, network detection, registry configuration. |
| [kubeblocks-manage-addons](./skills/kubeblocks-manage-addons/SKILL.md) | Install, uninstall, and upgrade database engine addons. |

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 64)May include surrounding context.

md
| Skill | Description |
|-------|-------------|
| [kubeblocks](./SKILL.md) | Entry point for all database tasks. Routes to the right skill based on user intent. |
| [kubeblocks-create-local-k8s-cluster](./skills/kubeblocks-create-local-k8s-cluster/SKILL.md) | Create a local Kubernetes test cluster using Kind, Minikube, or k3d. |
| [kubeblocks-install](./skills/kubeblocks-install/SKILL.md) | Install the KubeBlocks operator. Handles version selection, network detection, registry configuration. |
| [kubeblocks-manage-addons](./skills/kubeblocks-manage-addons/SKILL.md) | Install, uninstall, and upgrade database engine addons. |

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 21)May include surrounding context.

md
|-------|-------------|
| [kubeblocks](./SKILL.md) | Entry point for all database tasks. Routes to the right skill based on user intent. |
| [kubeblocks-create-local-k8s-cluster](./skills/kubeblocks-create-local-k8s-cluster/SKILL.md) | Create a local Kubernetes test cluster using Kind, Minikube, or k3d. |
| [kubeblocks-install](./skills/kubeblocks-install/SKILL.md) | Install the KubeBlocks operator. Handles version selection, network detection, registry configuration. |
| [kubeblocks-manage-addons](./skills/kubeblocks-manage-addons/SKILL.md) | Install, uninstall, and upgrade database engine addons. |

### Cluster Provisioning & Deletion

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

md
|-------|-------------|
| [kubeblocks](./SKILL.md) | Entry point for all database tasks. Routes to the right skill based on user intent. |
| [kubeblocks-create-local-k8s-cluster](./skills/kubeblocks-create-local-k8s-cluster/SKILL.md) | Create a local Kubernetes test cluster using Kind, Minikube, or k3d. |
| [kubeblocks-install](./skills/kubeblocks-install/SKILL.md) | Install the KubeBlocks operator. Handles version selection, network detection, registry configuration. |
| [kubeblocks-manage-addons](./skills/kubeblocks-manage-addons/SKILL.md) | Install, uninstall, and upgrade database engine addons. |

### Cluster Provisioning & Deletion

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 65)May include surrounding context.

md
|-------|-------------|
| [kubeblocks](./SKILL.md) | Entry point for all database tasks. Routes to the right skill based on user intent. |
| [kubeblocks-create-local-k8s-cluster](./skills/kubeblocks-create-local-k8s-cluster/SKILL.md) | Create a local Kubernetes test cluster using Kind, Minikube, or k3d. |
| [kubeblocks-install](./skills/kubeblocks-install/SKILL.md) | Install the KubeBlocks operator. Handles version selection, network detection, registry configuration. |
| [kubeblocks-manage-addons](./skills/kubeblocks-manage-addons/SKILL.md) | Install, uninstall, and upgrade database engine addons. |

### Cluster Provisioning & Deletion

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 22)May include surrounding context.

md
| [kubeblocks](./SKILL.md) | Entry point for all database tasks. Routes to the right skill based on user intent. |
| [kubeblocks-create-local-k8s-cluster](./skills/kubeblocks-create-local-k8s-cluster/SKILL.md) | Create a local Kubernetes test cluster using Kind, Minikube, or k3d. |
| [kubeblocks-install](./skills/kubeblocks-install/SKILL.md) | Install the KubeBlocks operator. Handles version selection, network detection, registry configuration. |
| [kubeblocks-manage-addons](./skills/kubeblocks-manage-addons/SKILL.md) | Install, uninstall, and upgrade database engine addons. |

### Cluster Provisioning & Deletion

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

md
| [kubeblocks](./SKILL.md) | Entry point for all database tasks. Routes to the right skill based on user intent. |
| [kubeblocks-create-local-k8s-cluster](./skills/kubeblocks-create-local-k8s-cluster/SKILL.md) | Create a local Kubernetes test cluster using Kind, Minikube, or k3d. |
| [kubeblocks-install](./skills/kubeblocks-install/SKILL.md) | Install the KubeBlocks operator. Handles version selection, network detection, registry configuration. |
| [kubeblocks-manage-addons](./skills/kubeblocks-manage-addons/SKILL.md) | Install, uninstall, and upgrade database engine addons. |

### Cluster Provisioning & Deletion

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README advertises destructive and operationally sensitive capabilities such as deletion, scaling, switchover, restore, upgrades, and external exposure without prominent warnings about downtime, data loss, credential rotation, or public network exposure. Because this skill targets production-grade databases on Kubernetes, missing warnings materially raise the risk of unsafe agent actions in real infrastructure.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.