Back to skill

Security audit

Kubernetes

Security checks for vulnerabilities and agentic risk

Overview

This Kubernetes troubleshooting skill is not malicious, but it needs review because it combines automatic infrastructure memory with high-privilege cluster debug commands and unfiltered secret-prone output.

Install only if you are comfortable with a skill that may guide an agent through powerful kubectl workflows and keep a local operational memory of your clusters. Use it with least-privilege Kubernetes credentials, require explicit confirmation for node debugging and secret-adjacent commands, prefer approved digest-pinned debug images, avoid full environment dumps unless absolutely necessary, and protect or periodically delete the local Clawic data directories.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
nodes.md:59
Finding

Privileged Kubernetes Node Debugging Exposes the Host Filesystem and Namespaces

Content
View full analysis
-it --image=busybox # node filesystem at /host, host namespaces chroot /host # then the usual tools crictl ps -a && crictl logs # container runtime view when kubectl cannot reach it journalctl -u kubelet -n 200 --no-pager # kubelet's own story df -h /var/lib/kubelet /var/lib/containerd && dmesg -T | tail -50 ``` The same privileged node-debug technique also appears in `commands.md:43`: ```bash kubectl debug node/ -it --image=busybox # node shell without SSH; host fs at /host ``` ### Technical Analysis `kubectl debug node/` creates a node-debugging pod with access to host namespaces and mounts the node filesystem at `/host`. Running `chroot /host` then changes the apparent root filesystem to that of the Kubernetes node. This access can expose: - Kubelet and node credentials. - Container runtime sockets and configuration. - Files belonging to other pods. - Mounted Secret material and ServiceAccount tokens. - Host logs and process information. - Host configuration that can be modified to affect all workloads on the node. Node-level diagnostics are consistent with the Skill's declared troubleshooting purpose. However, entering the complete host filesystem exceeds the minimum privilege required for many routine investigations. The documented flow does not impose a mandatory production-context check, explicit user authorization, read-only limitation, or command allowlist before invoking `chroot`. Exploitation requires the invoking Kubernetes identity already to have permission to create the node-debug pod. The documentation does not itself grant this permission, but it directs the Agent to exercise it at its full pri ...[truncated 1022 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
commands.md:42
Finding

Unfiltered Process Environment Dump Can Disclose Application Credentials

Content
View full analysis
--image=nicolaka/netshoot --target= # ephemeral container, shared PID ns (kubectl >=1.25) kubectl debug node/ -it --image=busybox # node shell without SSH; host fs at /host kubectl debug --copy-to=-dbg --set-image=app=busybox -- sleep 1d # clone with a debug image, original untouched kubectl exec

-c -- sh -c 'cat /proc/1/environ | tr "\0" "\n"' # what the process actually got kubectl cp /:/path/file ./file # pull a heap dump or core file out ``` ### Technical Analysis The command reads the complete environment of process ID 1 inside the selected container and prints every variable in plaintext. Kubernetes applications frequently receive sensitive values through environment variables, including: - Database usernames and passwords. - API tokens. - Cloud access credentials. - OAuth client secrets. - Webhook or monitoring tokens. - Internal service URLs containing embedded credentials. Although the Skill separately prohibits writing credentials into its persistent memory files, that protection does not prevent secrets from appearing in terminal output, conversation transcripts, Agent context, command logs, shell history, or observability systems. The command also lacks a warning, filtering mechanism, redaction stage, or explicit confirmation requirement. ### Attack Path 1. The invoking identity has `pods/exec` permission for a credential-bearing pod. 2. The documented command is executed against the pod. 3. `/proc/1/environ` is converted into newline-delimited plaintext. 4. All environment-variable names and values are printed to standard output. 5. Credentials are captured in the terminal, Agent transcript, API logs, or another o ...[truncated 547 chars]

Remediation
View remediation
-c -- printenv APP_MODE ``` 3. Require explicit confirmation before inspecting a full process environment. 4. Display a warning that environment output may contain passwords, tokens, or cloud credentials. 5. Pipe output through a robust redaction mechanism before returning it to the Agent or user. 6. Avoid placing raw output in persistent files, transcripts, tickets, or chat systems. 7. Prefer checking Kubernetes configuration references and variable names without reading their values. 8. Restrict `pods/exec` RBAC to operators who require it and audit its use. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
commands.md:7
Finding

Predictable Shared Temporary Files Are Used for Potentially Sensitive Kubernetes Evidence

Content
View full analysis
> /tmp/pod.txt # events + probe + OOM history in one file kubectl get pod

-o yaml > /tmp/pod.yaml # status.containerStatuses.lastState is the crash record kubectl logs

-p --tail=200 # previous container after a restart kubectl logs

--all-containers --timestamps --since=15m # sidecars included; timestamps for correlation ``` ### Technical Analysis The evidence-capture commands write Kubernetes output to fixed paths under the shared `/tmp` directory. Fixed temporary filenames introduce several risks: - Another local user may predict and read the output. - An attacker may pre-create a symbolic link at the path before redirection. - Existing evidence may be silently overwritten. - Files may remain after the troubleshooting session. - Default process permissions may make the resulting files readable by unintended users. Pod YAML and descriptions can contain sensitive operational information, including internal addresses, annotations, environment values, image names, security settings, node placement, mounted Secret names, and incident details. Shell redirection opens the destination before `kubectl` runs. If an attacker can prepare a malicious link and the Agent runs with sufficient filesystem privileges, the output may overwrite another writable target. ### Attack Path 1. A local attacker predicts `/tmp/pod.txt` or `/tmp/pod.yaml`. 2. The attacker monitors the file or pre-creates it as a symbolic link. 3. The Agent executes the documented redirection. 4. Kubernetes evidence is written to the attacker-observable file or linked destination. 5. The attacker reads operational data, or an unintended ta ...[truncated 503 chars]

Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
commands.md:42
Finding

Mutable Third-Party Debug Images Are Executed in Sensitive Kubernetes Contexts

Content
View full analysis
--image=nicolaka/netshoot --target= # ephemeral container, shared PID ns (kubectl >=1.25) kubectl debug node/ -it --image=busybox # node shell without SSH; host fs at /host kubectl debug --copy-to=-dbg --set-image=app=busybox -- sleep 1d # clone with a debug image, original untouched kubectl exec

-c -- sh -c 'cat /proc/1/environ | tr "\0" "\n"' # what the process actually got kubectl cp /:/path/file ./file # pull a heap dump or core file out ``` Additional unpinned `busybox` node-debug usage appears in `nodes.md:61`. ### Technical Analysis The debug commands use `nicolaka/netshoot` and `busybox` without immutable digests. A mutable image tag may resolve to different content over time, so the code executed during a future debugging session is not necessarily the code reviewed when this Skill was audited. This conflicts with the Skill's own security guidance to pin production images by digest. The risk is especially severe for the `busybox` image used by `kubectl debug node`, because that image can run with host namespace and filesystem access. Relevant compromise scenarios include: - An upstream registry account is compromised. - A mutable tag is replaced or republished. - A registry mirror is compromised or misconfigured. - Name-resolution or registry policy directs the pull to an unintended source. - An operator assumes that a familiar image name implies trusted contents. ### Attack Path 1. A mutable debug image tag is replaced upstream or resolves through a compromised registry path. 2. The Agent invokes one of the documented debug commands. 3. Kubernetes pulls the current image associated with that tag. 4. The altered image executes ...[truncated 702 chars]

Remediation
View remediation
``` 2. Mirror approved diagnostic images into a controlled internal registry. 3. Enforce image-signature verification through admission policy. 4. Apply a registry allowlist to debugging and ephemeral-container images. 5. Maintain a documented update process for approved digests and rescan images before promotion. 6. Use separate minimal images for pod-level and node-level diagnostics. 7. Do not permit arbitrary user-provided debug image names in privileged node workflows. 8. Configure audit alerts for ephemeral containers and node-debug pods using unapproved images. ]]>

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:37
Finding

Automatic Cross-Session Infrastructure Inventory Creates a Concentrated Reconnaissance Dataset

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (56)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 76)May include surrounding context.

md
| StatefulSet pod-0 won't start | Ordered rollout blocks on the previous ordinal; a retained PVC may hold stale data → `stateful.md` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 90)May include surrounding context.

md
| StatefulSet pod-0 won't start | Ordered rollout blocks on the previous ordinal; a retained PVC may hold stale data → `stateful.md` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 238)May include surrounding context.

md
| StatefulSet pod-0 won't start | Ordered rollout blocks on the previous ordinal; a retained PVC may hold stale data → `stateful.md` |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · commands.md (reported line 57)May include surrounding context.

bash
kubectl get endpointslices -l kubernetes.io/service-name=<svc> -o wide   # the truth about wiring
kubectl port-forward svc/<svc> 8080:80        # bypasses Ingress and LB — isolates which layer is broken
kubectl run tmp --rm -it --image=nicolaka/netshoot --restart=Never -- bash
kubectl exec <p> -- getent hosts <svc>        # portable resolution test (musl and glibc both have it)

Privileged Kubernetes Workload

High
Category
Tool Misuse
Confidence
70% confidence
Finding

Code deploys a privileged Kubernetes workload (privileged container, hostPath mount, or host namespaces). This grants root on the node and is a node/cluster takeover vector.

Content

Scanner excerpt · daemonsets.md (reported line 33)May include surrounding context.

md
## Privileges, Legitimately

- This is the one workload class where `hostNetwork`, `hostPID`, `hostPath`, and specific capabilities are a design rather than a finding — a CNI agent cannot do its job inside a pod network namespace.
- Make the exception visible: a dedicated namespace labelled `pod-security.kubernetes.io/enforce: privileged`, one ServiceAccount per agent, and the narrowest capability set that works instead of `privileged: true` (`security.md`).
- Audit what they can read. An agent mounting `/var/lib/kubelet` can read every pod's Secrets on that node, and its ServiceAccount is often cluster-wide read. A compromised logging agent is a cluster-wide credential compromise (`rbac.md`).
- Prefer `hostPath` mounts as `readOnly` wherever the agent only observes, and pin the paths — `/var/log/pods` and `/var/lib/docker/containers`, never `/`.

Privileged Kubernetes Workload

High
Category
Tool Misuse
Confidence
70% confidence
Finding

Code deploys a privileged Kubernetes workload (privileged container, hostPath mount, or host namespaces). This grants root on the node and is a node/cluster takeover vector.

Content

Scanner excerpt · security.md (reported line 49)May include surrounding context.

md
## Privileges, Legitimately

- This is the one workload class where `hostNetwork`, `hostPID`, `hostPath`, and specific capabilities are a design rather than a finding — a CNI agent cannot do its job inside a pod network namespace.
- Make the exception visible: a dedicated namespace labelled `pod-security.kubernetes.io/enforce: privileged`, one ServiceAccount per agent, and the narrowest capability set that works instead of `privileged: true` (`security.md`).
- Audit what they can read. An agent mounting `/var/lib/kubelet` can read every pod's Secrets on that node, and its ServiceAccount is often cluster-wide read. A compromised logging agent is a cluster-wide credential compromise (`rbac.md`).
- Prefer `hostPath` mounts as `readOnly` wherever the agent only observes, and pin the paths — `/var/log/pods` and `/var/lib/docker/containers`, never `/`.

Privileged Kubernetes Workload

High
Category
Tool Misuse
Confidence
60% confidence
Finding

Code deploys a privileged Kubernetes workload (privileged container, hostPath mount, or host namespaces). This grants root on the node and is a node/cluster takeover vector.

Content

Scanner excerpt · dns.md (reported line 35)May include surrounding context.

md
| Value | Resolver | Use |
|---|---|---|
| `ClusterFirst` | Cluster DNS, forwarding external names upstream | Default; correct for almost everything |
| `ClusterFirstWithHostNet` | Same, but required when `hostNetwork: true` | Host-network pods that still need cluster names |
| `Default` | Inherits the node's resolv.conf | Pods that must resolve exactly like the node |
| `None` | Nothing; you supply `dnsConfig` entirely | Custom resolvers, split-horizon corporate DNS |

Privileged Kubernetes Workload

High
Category
Tool Misuse
Confidence
60% confidence
Finding

Code deploys a privileged Kubernetes workload (privileged container, hostPath mount, or host namespaces). This grants root on the node and is a node/cluster takeover vector.

Content

Scanner excerpt · dns.md (reported line 39)May include surrounding context.

md
| Value | Resolver | Use |
|---|---|---|
| `ClusterFirst` | Cluster DNS, forwarding external names upstream | Default; correct for almost everything |
| `ClusterFirstWithHostNet` | Same, but required when `hostNetwork: true` | Host-network pods that still need cluster names |
| `Default` | Inherits the node's resolv.conf | Pods that must resolve exactly like the node |
| `None` | Nothing; you supply `dnsConfig` entirely | Custom resolvers, split-horizon corporate DNS |

Privileged Kubernetes Workload

High
Category
Tool Misuse
Confidence
60% confidence
Finding

Code deploys a privileged Kubernetes workload (privileged container, hostPath mount, or host namespaces). This grants root on the node and is a node/cluster takeover vector.

Content

Scanner excerpt · networking.md (reported line 80)May include surrounding context.

md
| Value | Resolver | Use |
|---|---|---|
| `ClusterFirst` | Cluster DNS, forwarding external names upstream | Default; correct for almost everything |
| `ClusterFirstWithHostNet` | Same, but required when `hostNetwork: true` | Host-network pods that still need cluster names |
| `Default` | Inherits the node's resolv.conf | Pods that must resolve exactly like the node |
| `None` | Nothing; you supply `dnsConfig` entirely | Custom resolvers, split-horizon corporate DNS |

Privileged Kubernetes Workload

High
Category
Tool Misuse
Confidence
60% confidence
Finding

Code deploys a privileged Kubernetes workload (privileged container, hostPath mount, or host namespaces). This grants root on the node and is a node/cluster takeover vector.

Content

Scanner excerpt · security.md (reported line 51)May include surrounding context.

md
| Value | Resolver | Use |
|---|---|---|
| `ClusterFirst` | Cluster DNS, forwarding external names upstream | Default; correct for almost everything |
| `ClusterFirstWithHostNet` | Same, but required when `hostNetwork: true` | Host-network pods that still need cluster names |
| `Default` | Inherits the node's resolv.conf | Pods that must resolve exactly like the node |
| `None` | Nothing; you supply `dnsConfig` entirely | Custom resolvers, split-horizon corporate DNS |

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 90)May include surrounding context.

bash
kubectl config current-context                      # before every destructive command
kubectl config get-contexts                         # what is even in this kubeconfig
kubectl --context=kind-dev apply -f .               # explicit beats remembering

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 182)May include surrounding context.

bash
kubectl config current-context                      # before every destructive command
kubectl config get-contexts                         # what is even in this kubeconfig
kubectl --context=kind-dev apply -f .               # explicit beats remembering

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · config-and-secrets.md (reported line 68)May include surrounding context.

bash
kubectl config current-context                      # before every destructive command
kubectl config get-contexts                         # what is even in this kubeconfig
kubectl --context=kind-dev apply -f .               # explicit beats remembering

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · local-dev.md (reported line 9)May include surrounding context.

bash
kubectl config current-context                      # before every destructive command
kubectl config get-contexts                         # what is even in this kubeconfig
kubectl --context=kind-dev apply -f .               # explicit beats remembering

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · local-dev.md (reported line 15)May include surrounding context.

bash
kubectl config current-context                      # before every destructive command
kubectl config get-contexts                         # what is even in this kubeconfig
kubectl --context=kind-dev apply -f .               # explicit beats remembering

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · local-dev.md (reported line 18)May include surrounding context.

bash
kubectl config current-context                      # before every destructive command
kubectl config get-contexts                         # what is even in this kubeconfig
kubectl --context=kind-dev apply -f .               # explicit beats remembering

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · local-dev.md (reported line 59)May include surrounding context.

bash
kubectl config current-context                      # before every destructive command
kubectl config get-contexts                         # what is even in this kubeconfig
kubectl --context=kind-dev apply -f .               # explicit beats remembering

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · memory-template.md (reported line 19)May include surrounding context.

bash
kubectl config current-context                      # before every destructive command
kubectl config get-contexts                         # what is even in this kubeconfig
kubectl --context=kind-dev apply -f .               # explicit beats remembering

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · memory-template.md (reported line 55)May include surrounding context.

bash
kubectl config current-context                      # before every destructive command
kubectl config get-contexts                         # what is even in this kubeconfig
kubectl --context=kind-dev apply -f .               # explicit beats remembering

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · memory-template.md (reported line 61)May include surrounding context.

bash
kubectl config current-context                      # before every destructive command
kubectl config get-contexts                         # what is even in this kubeconfig
kubectl --context=kind-dev apply -f .               # explicit beats remembering

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · memory-template.md (reported line 189)May include surrounding context.

bash
kubectl config current-context                      # before every destructive command
kubectl config get-contexts                         # what is even in this kubeconfig
kubectl --context=kind-dev apply -f .               # explicit beats remembering

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 45)May include surrounding context.

md
- The failure shape is always the same: a `delete`, `scale --replicas=0`, or `apply` that was correct for dev, executed against prod because a previous command switched the context. Nothing in kubectl warns you.
- Make the current context visible in the shell prompt. A prompt segment showing context and namespace is the cheapest incident prevention in this file.
- Separate kubeconfig files per environment (`KUBECONFIG=~/.kube/prod.yaml`) beat one file with many contexts: switching becomes an explicit act, and a stale context cannot follow you into a new terminal.
- Give production contexts names that read as a warning (`prod-eu-DANGER`), and where the platform supports it, use read-only credentials by default with a separate escalation path.
- `--dry-run=server` and `kubectl diff` are also context-safety tools: both show you which cluster answered before anything changes (`manifests.md`).
- Automation never inherits an ambient context: CI and scripts pass `--context` or a dedicated kubeconfig explicitly, and `destructive_confirm` governs whether a destructive command is proposed or executed.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · local-dev.md (reported line 15)May include surrounding context.

md
- The failure shape is always the same: a `delete`, `scale --replicas=0`, or `apply` that was correct for dev, executed against prod because a previous command switched the context. Nothing in kubectl warns you.
- Make the current context visible in the shell prompt. A prompt segment showing context and namespace is the cheapest incident prevention in this file.
- Separate kubeconfig files per environment (`KUBECONFIG=~/.kube/prod.yaml`) beat one file with many contexts: switching becomes an explicit act, and a stale context cannot follow you into a new terminal.
- Give production contexts names that read as a warning (`prod-eu-DANGER`), and where the platform supports it, use read-only credentials by default with a separate escalation path.
- `--dry-run=server` and `kubectl diff` are also context-safety tools: both show you which cluster answered before anything changes (`manifests.md`).
- Automation never inherits an ambient context: CI and scripts pass `--context` or a dedicated kubeconfig explicitly, and `destructive_confirm` governs whether a destructive command is proposed or executed.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · memory-template.md (reported line 57)May include surrounding context.

md
- The failure shape is always the same: a `delete`, `scale --replicas=0`, or `apply` that was correct for dev, executed against prod because a previous command switched the context. Nothing in kubectl warns you.
- Make the current context visible in the shell prompt. A prompt segment showing context and namespace is the cheapest incident prevention in this file.
- Separate kubeconfig files per environment (`KUBECONFIG=~/.kube/prod.yaml`) beat one file with many contexts: switching becomes an explicit act, and a stale context cannot follow you into a new terminal.
- Give production contexts names that read as a warning (`prod-eu-DANGER`), and where the platform supports it, use read-only credentials by default with a separate escalation path.
- `--dry-run=server` and `kubectl diff` are also context-safety tools: both show you which cluster answered before anything changes (`manifests.md`).
- Automation never inherits an ambient context: CI and scripts pass `--context` or a dedicated kubeconfig explicitly, and `destructive_confirm` governs whether a destructive command is proposed or executed.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · memory-template.md (reported line 19)May include surrounding context.

md
| Things you produced that get re-read — runbooks, a NetworkPolicy or Role that finally worked, architecture decisions, capacity plans, upgrade plans | `~/Clawic/data/k8s/artifacts/<kebab-name>.md` | Born as its own file, from the first one |
| Deploy records, cluster upgrades, and timed restore drills | `~/Clawic/data/k8s/deploys/<year>.md` | Append-only, cut by year |
| **Anything durable this table does not name** | `~/Clawic/data/k8s/<plural-noun>.md`, or `artifacts/<kebab-name>.md` if it is a long text read whole | Name the file after what it holds, never after when it was made; add its `## Boxes` line in the same turn |
| Kubeconfigs, tokens, kubeconfig contents, Secret values | Nowhere under `~/Clawic/data/` | Pointer only — see Secrets |

## When to write

Static analysis

No suspicious patterns detected.