Back to skill

Security audit

K8s Yaml Connect

Security checks for vulnerabilities and agentic risk

Overview

This Kubernetes skill is mostly purpose-aligned, but it handles cluster credentials and mutable kubectl access with unsafe file-storage and persistence patterns users should review before installing.

Install only if you are comfortable with a skill that can apply Kubernetes resources and switch/use kubeconfig credentials. Before use, replace the /tmp kubeconfig workflow with mktemp plus mode 0600, avoid long-lived copied kubeconfig files, verify the current context and namespace before kubectl apply, and clean up temporary credential files.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:90
Finding

Predictable Shared Temporary Kubeconfig Path Enables Credential Disclosure and File Overwrite

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 90–95
Vulnerability Type: Predictable insecure temporary file containing sensitive credentials
Risk Level: High

bash
cat > /tmp/kubeconfig.yaml <<'EOF'
[KUBECONFIG_YAML]
EOF

# Set KUBECONFIG environment variable
export KUBECONFIG=/tmp/kubeconfig.yaml

Technical Analysis

The documented workflow writes a Kubernetes kubeconfig to the fixed, globally predictable path /tmp/kubeconfig.yaml. Kubeconfig files can contain bearer tokens, client private keys, client certificates, and other credentials.

Shell redirection follows symbolic links. A local attacker can therefore create /tmp/kubeconfig.yaml as a symbolic link before the workflow is executed. The redirection would truncate and replace the linked destination if the user running the command has permission to write to it. If no link exists, the permissions of the newly created file depend on the user's current umask; the workflow does not explicitly require mode 0600.

Attack Path

  1. A local attacker predicts the documented /tmp/kubeconfig.yaml filename.
  2. The attacker either monitors the path for a permissively created file or creates a symbolic link at that path to a file writable by the victim.
  3. The user or agent follows the Skill instructions and redirects kubeconfig content into the predictable path.
  4. If a symbolic link is present, the shell follows it and overwrites the target. Otherwise, an insufficiently restrictive umask may make the kubeconfig readable to other local users.
  5. The attacker obtains Kubernetes credentials or causes corruption of another victim-writable file.

Impact Assessment

Exposed credentials allow access with the identity and RBAC permissions contained in the kubeconfig. Depending on that identity, the impact can include reading cluster resources, accessing Kubernetes Secrets, modifying workloads, or administering the cluster. ...[truncated 200 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace the fixed path with a securely generated file created by mktemp.
  • Set umask 077 before creating any credential-bearing file.
  • Ensure the file is newly created and is not a symbolic link.
  • Explicitly enforce mode 0600, for example with install -m 600.
  • Register an exit trap to remove temporary kubeconfig files:
    bash
    umask 077
    KUBECONFIG_FILE="$(mktemp)"
    trap 'rm -f -- "$KUBECONFIG_FILE"' EXIT HUP INT TERM
    
  • Avoid placing long-lived credentials in a shared temporary directory where possible.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/set-kubeconfig.sh:65
Finding

Persistent Kubeconfig Copies Are Created Without Enforcing Restrictive Permissions

Content
View full analysis

Vulnerability Details

File Location: scripts/set-kubeconfig.sh, lines 65–80
Vulnerability Type: Insecure storage of credential-bearing configuration
Risk Level: Medium

bash
# Create kubeconfig file
if [[ "$TEMP" == true ]]; then
    KUBECONFIG_FILE=$(mktemp)
    echo "Using temporary kubeconfig: $KUBECONFIG_FILE"
else
    KUBECONFIG_FILE="$HOME/.kube/config-$(date +%Y%m%d-%H%M%S)"
    echo "Creating new kubeconfig: $KUBECONFIG_FILE"
fi

# Write kubeconfig
if [[ "$FILE" == "-" ]]; then
    echo "Reading kubeconfig YAML from stdin..."
    cat > "$KUBECONFIG_FILE"
else
    echo "Reading kubeconfig YAML from file: $FILE"
    cp "$FILE" "$KUBECONFIG_FILE"
fi

Technical Analysis

In non-temporary mode, the script creates a timestamped kubeconfig under $HOME/.kube and copies credential-bearing content into it. The script does not set umask 077, explicitly apply mode 0600, or otherwise verify the resulting permissions.

When content is written with shell redirection, the resulting mode depends on the caller's umask. When cp creates the destination, its effective permissions can also be influenced by the source mode and process umask. Consequently, a permissive environment can produce a kubeconfig readable by other local principals.

Timestamped copies also accumulate instead of replacing or securely retiring an existing configuration, increasing the number and lifetime of files containing potentially valid credentials.

Attack Path

  1. A user supplies a kubeconfig containing a token, private key, or client certificate.
  2. The script creates a timestamped persistent copy under $HOME/.kube.
  3. The process runs with a permissive umask or copies permissive source permissions.
  4. Another local user or compromised process enumerates the kubeconfig files and reads the exposed copy.
  5. The attacker uses the recovered credentials against the configured Kubernetes API ...[truncated 345 chars]
Remediation
View remediation

Remediation Suggestions

  • Set umask 077 near the beginning of the script, before creating any files.
  • Create $HOME/.kube when necessary and enforce directory mode 0700.
  • Create destination files atomically with mode 0600.
  • Use install -m 600 -- "$FILE" "$KUBECONFIG_FILE" rather than relying on cp.
  • After writing from standard input, explicitly verify and enforce mode 0600.
  • Avoid unnecessary timestamped credential copies, or implement a documented retention and secure-deletion policy.
  • Validate that the destination is a regular file owned by the current user before using it.

T09 · Insecure Skill Coding Practices

Note
Location
scripts/set-kubeconfig.sh:66
Finding

Temporary Kubeconfig Containing Cluster Credentials Is Never Removed

Content
View full analysis

Vulnerability Details

File Location: scripts/set-kubeconfig.sh, lines 66–80
Vulnerability Type: Sensitive temporary file retention
Risk Level: Low

bash
if [[ "$TEMP" == true ]]; then
    KUBECONFIG_FILE=$(mktemp)
    echo "Using temporary kubeconfig: $KUBECONFIG_FILE"
else
    KUBECONFIG_FILE="$HOME/.kube/config-$(date +%Y%m%d-%H%M%S)"
    echo "Creating new kubeconfig: $KUBECONFIG_FILE"
fi

# Write kubeconfig
if [[ "$FILE" == "-" ]]; then
    echo "Reading kubeconfig YAML from stdin..."
    cat > "$KUBECONFIG_FILE"
else
    echo "Reading kubeconfig YAML from file: $FILE"
    cp "$FILE" "$KUBECONFIG_FILE"
fi

Technical Analysis

mktemp securely creates a unique temporary file, but the script never registers a cleanup trap and never deletes that file. Thus, the --temp option does not make the credential file temporary in terms of lifecycle.

The file may remain after successful execution, connection failure, invalid context selection, interruption, or another early exit caused by set -e. Although mktemp normally creates a restrictively permissioned file, credentials remain on disk indefinitely and are available to any process that later gains access to the account or sufficient local privileges.

Attack Path

  1. A user runs set-kubeconfig.sh --temp with a credential-bearing kubeconfig.
  2. The script copies the kubeconfig into a file generated by mktemp.
  3. The script exits normally or through an error path without deleting the file.
  4. A process that later compromises the account, or a sufficiently privileged local attacker, searches the temporary directory for abandoned files.
  5. The attacker recovers the kubeconfig and uses any credentials that remain valid.

Impact Assessment

The issue extends the exposure period of Kubernetes tokens, certificates, and private keys beyond the intended Skill invocation. Recovered credentials provide the RBAC privil ...[truncated 114 chars]

Remediation
View remediation

Remediation Suggestions

  • Install a cleanup trap immediately after successful temporary-file creation:
    bash
    if [[ "$TEMP" == true ]]; then
        KUBECONFIG_FILE="$(mktemp)"
        trap 'rm -f -- "$KUBECONFIG_FILE"' EXIT HUP INT TERM
    fi
    
  • Keep restrictive permissions by setting umask 077.
  • Ensure every success, failure, and signal-handling path removes the temporary file.
  • If the file must remain available after the script exits, do not describe it as temporary; instead, document its lifecycle and provide an explicit cleanup command.
  • Prefer short-lived Kubernetes credentials so that abandoned files have limited value.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (63)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 49)May include surrounding context.

./scripts/validate-yaml.sh -s -f deployment.yaml

text

### Set Kubeconfig from YAML
```bash
# Load kubeconfig and switch context
./scripts/set-kubeconfig.sh -f kubeconfig.yaml -c production

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The code does support part of the description: applying Kubernetes YAML from a file or stdin, optional dry-run validation, namespace targeting, and use of kubectl against the current cluster context. However, the declared purpose also claims handling kubeconfig creation and context switching, which are not present in the code. The script only uses the already-configured current context and checks connectivity; it does not establish new cluster configs or switch contexts. Therefore the description materially overstates the implemented capabilities.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The code is narrowly focused on kubeconfig setup and connection testing. It does accurately cover kubeconfig creation from YAML, context listing/switching, and cluster connectivity verification. However, the declared description also claims use for applying, validating, or managing Kubernetes resources via kubectl with YAML input and resource deployment from YAML content. None of those resource-management behaviors appear in the supplied code chunk. This is a material description/behavior mismatch because the declared primary capability is broader than what the implementation actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The description claims a broader Kubernetes management capability centered on connecting to clusters and managing resources, including kubeconfig handling and context switching. The actual script only validates YAML syntax/configuration locally via kubectl --dry-run=client and optional validation/linting tools. While validation is one subset of the declared purpose, the central cluster-connection and resource-management behaviors are absent. Therefore the description materially overstates what the code chunk does.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
89% confidence
Finding

This section begins a workflow for handling kubeconfig YAML, which frequently embeds credentials or references secret material. In a Kubernetes access skill, encouraging direct manipulation of kubeconfig without strong safeguards increases risk of credential leakage and accidental cluster access changes.

Content

Scanner excerpt · SKILL.md (reported line 85)May include surrounding context.

EOF

text

### 3. Create/Update Kubeconfig from YAML
If you have kubeconfig YAML, save it and update context:

```bash

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Telling users to 'save kubeconfig' normalizes writing potentially sensitive cluster credentials to disk without protective guidance. If the source YAML is untrusted or the storage location is weakly protected, this can expose credentials or authorize operations against an unintended cluster.

Content

Scanner excerpt · SKILL.md (reported line 86)May include surrounding context.

text

### 3. Create/Update Kubeconfig from YAML
If you have kubeconfig YAML, save it and update context:

```bash
# Save kubeconfig

Credential Access

High
Category
Privilege Escalation
Confidence
96% confidence
Finding

Writing kubeconfig content to /tmp/kubeconfig.yaml is risky because /tmp is a shared temporary location and kubeconfig may contain active credentials, certificates, and cluster endpoints. This can lead to credential disclosure, tampering, or reuse by other local processes/users depending on system configuration and permissions.

Content

Scanner excerpt · SKILL.md (reported line 89)May include surrounding context.

If you have kubeconfig YAML, save it and update context:

bash
# Save kubeconfig
cat > /tmp/kubeconfig.yaml <<'EOF'
[KUBECONFIG_YAML]
EOF

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

Embedding raw kubeconfig YAML in a heredoc encourages direct pasting of secret-bearing configuration into shell workflows, where it may be captured in terminal logs, histories, or surrounding tooling. In the Kubernetes context, those secrets can grant broad cluster access if exposed.

Content

Scanner excerpt · SKILL.md (reported line 90)May include surrounding context.

bash
# Save kubeconfig
cat > /tmp/kubeconfig.yaml <<'EOF'
[KUBECONFIG_YAML]
EOF

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The instruction to set KUBECONFIG is not malicious by itself, but it changes the credential source and effective cluster target for subsequent kubectl commands. Without a warning, users may unknowingly operate on a different cluster context than intended, causing misdeployment or administrative mistakes.

Content

Scanner excerpt · SKILL.md (reported line 91)May include surrounding context.

bash
# Save kubeconfig
cat > /tmp/kubeconfig.yaml <<'EOF'
[KUBECONFIG_YAML]
EOF

# Set KUBECONFIG environment variable

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Exporting KUBECONFIG=/tmp/kubeconfig.yaml persists an altered credential/context setting for the shell session and references an insecure temporary location. This combination can both expose sensitive config material and redirect operations to an unintended cluster.

Content

Scanner excerpt · SKILL.md (reported line 94)May include surrounding context.

md
[KUBECONFIG_YAML]
EOF

# Set KUBECONFIG environment variable
export KUBECONFIG=/tmp/kubeconfig.yaml

# Verify connection

Credential Access

High
Category
Privilege Escalation
Confidence
84% confidence
Finding

The reference to kubeconfig here is part of a sequence that can activate and use sensitive cluster credentials. While the word itself is not dangerous, the surrounding workflow lacks safeguards against credential exposure and unintended cluster targeting.

Content

Scanner excerpt · SKILL.md (reported line 95)May include surrounding context.

md
EOF

# Set KUBECONFIG environment variable
export KUBECONFIG=/tmp/kubeconfig.yaml

# Verify connection
kubectl cluster-info

Credential Access

High
Category
Privilege Escalation
Confidence
84% confidence
Finding

The reference to kubeconfig here is part of a sequence that can activate and use sensitive cluster credentials. While the word itself is not dangerous, the surrounding workflow lacks safeguards against credential exposure and unintended cluster targeting.

Content

Scanner excerpt · SKILL.md (reported line 95)May include surrounding context.

md
EOF

# Set KUBECONFIG environment variable
export KUBECONFIG=/tmp/kubeconfig.yaml

# Verify connection
kubectl cluster-info

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 9)May include surrounding context.

md
#!/bin/bash
# set-kubeconfig.sh - Set kubeconfig from YAML

set -e

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 51)May include surrounding context.

md
#!/bin/bash
# set-kubeconfig.sh - Set kubeconfig from YAML

set -e

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 52)May include surrounding context.

md
#!/bin/bash
# set-kubeconfig.sh - Set kubeconfig from YAML

set -e

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 55)May include surrounding context.

md
#!/bin/bash
# set-kubeconfig.sh - Set kubeconfig from YAML

set -e

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 75)May include surrounding context.

md
#!/bin/bash
# set-kubeconfig.sh - Set kubeconfig from YAML

set -e

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 76)May include surrounding context.

md
#!/bin/bash
# set-kubeconfig.sh - Set kubeconfig from YAML

set -e

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 79)May include surrounding context.

md
#!/bin/bash
# set-kubeconfig.sh - Set kubeconfig from YAML

set -e

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 105)May include surrounding context.

md
#!/bin/bash
# set-kubeconfig.sh - Set kubeconfig from YAML

set -e

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
#!/bin/bash
# set-kubeconfig.sh - Set kubeconfig from YAML

set -e

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 15)May include surrounding context.

md
#!/bin/bash
# set-kubeconfig.sh - Set kubeconfig from YAML

set -e

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 270)May include surrounding context.

md
#!/bin/bash
# set-kubeconfig.sh - Set kubeconfig from YAML

set -e

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/set-kubeconfig.sh (reported line 2)May include surrounding context.

sh
#!/bin/bash
# set-kubeconfig.sh - Set kubeconfig from YAML

set -e

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/set-kubeconfig.sh (reported line 10)May include surrounding context.

sh
#!/bin/bash
# set-kubeconfig.sh - Set kubeconfig from YAML

set -e

Static analysis

No suspicious patterns detected.