Back to skill

Security audit

Kubernetes Agent Swarm

Security checks for vulnerabilities and agentic risk

Overview

This instruction-only Kubernetes operations skill is purpose-aligned overall, but it gives agents broad cluster and repository authority with several under-scoped ways to persist or disclose sensitive operational data.

Install only in a controlled operations environment after narrowing kubeconfig and cloud permissions, disabling or rewriting the git add -A commit and auto-PR workflows, adding strict redaction rules for logs and alerts, and requiring explicit approval for upgrades, secret reads, and external incident transmissions.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
skills/orchestrator/SKILL.md:564
Finding

Mandatory Repository-Wide Git Staging Can Commit Sensitive and Unrelated Files

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
skills/cluster-ops/SKILL.md:272
Finding

Cloud and Cluster Credential Commands Print Sensitive Values into Agent-Visible Output

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
skills/gitops/SKILL.md:728
Finding

Secret Creation Examples Pass Plaintext Passwords Through Command-Line Arguments

Content
View full analysis
Remediation
View remediation

other

Warning
Location
skills/orchestrator/SKILL.md:775
Finding

Timeout-Based PagerDuty Escalation Can Disclose Cluster and Incident Data Without Per-Transmission Approval

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (105)

Credential Access

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

md
- AZURE_TENANT_ID
    - GOOGLE_APPLICATION_CREDENTIALS
  credentials:
    - kubeconfig: "KUBECONFIG path or ~/.kube/config for cluster access"
    - cloud: "Optional cloud provider credentials for managed clusters (AWS/Azure/GCP)"
    - registry: "Optional container registry credentials for image operations"
---

Credential Access

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 60)May include surrounding context.

md
- AZURE_TENANT_ID
    - GOOGLE_APPLICATION_CREDENTIALS
  credentials:
    - kubeconfig: "KUBECONFIG path or ~/.kube/config for cluster access"
    - cloud: "Optional cloud provider credentials for managed clusters (AWS/Azure/GCP)"
    - registry: "Optional container registry credentials for image operations"
---

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

AKS upgrade commands are high-impact control-plane and node changes, yet the section lacks an explicit warning or approval requirement. In a cluster-operations skill, these commands are contextually plausible, but that same plausibility makes unsafe autonomous execution more dangerous because upgrades can cause outages, incompatibilities, or irreversible drift.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The GKE upgrade section documents master and node-pool upgrades without an explicit warning despite their high operational risk. Such commands can impact production availability and compatibility, and the lack of execution safeguards encourages unsafe use by agents or operators following the instructions verbatim.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

ARO upgrades are high-impact cluster mutations, but the section does not warn users to obtain approval first. In this operational context, missing guardrails materially increase the risk of service disruption because an agent may treat the examples as standard procedure and execute them prematurely.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
84% confidence
Finding

Calling kubeconfig 'cluster access credentials' without a security warning normalizes distribution of highly sensitive access material. If operators follow this guidance casually, leaked or improperly stored kubeconfigs could provide unauthorized cluster access and lateral movement opportunities.

Content

Scanner excerpt · skills/developer-experience/SKILL.md (reported line 593)May include surrounding context.

md
2. **Set up RBAC** — team gets edit role in their namespaces
3. **Create pull secrets** — for container registry access
4. **Create ArgoCD project** — limit which clusters/namespaces team can deploy to
5. **Generate kubeconfig** — cluster access credentials
6. **Share documentation** — platform guides, examples, runbooks

### Platform Documentation Topics

Credential Access

High
Category
Privilege Escalation
Confidence
84% confidence
Finding

Calling kubeconfig 'cluster access credentials' without a security warning normalizes distribution of highly sensitive access material. If operators follow this guidance casually, leaked or improperly stored kubeconfigs could provide unauthorized cluster access and lateral movement opportunities.

Content

Scanner excerpt · skills/developer-experience/SKILL.md (reported line 593)May include surrounding context.

md
2. **Set up RBAC** — team gets edit role in their namespaces
3. **Create pull secrets** — for container registry access
4. **Create ArgoCD project** — limit which clusters/namespaces team can deploy to
5. **Generate kubeconfig** — cluster access credentials
6. **Share documentation** — platform guides, examples, runbooks

### Platform Documentation Topics

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skills/gitops/SKILL.md (reported line 311)May include surrounding context.

md
│   ├── service.yaml
│   ├── ingress.yaml
│   ├── configmap.yaml
│   ├── secret.yaml
│   ├── hpa.yaml
│   ├── pdb.yaml
│   ├── serviceaccount.yaml

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skills/gitops/SKILL.md (reported line 664)May include surrounding context.

md
│   ├── service.yaml
│   ├── ingress.yaml
│   ├── configmap.yaml
│   ├── secret.yaml
│   ├── hpa.yaml
│   ├── pdb.yaml
│   ├── serviceaccount.yaml

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skills/gitops/SKILL.md (reported line 667)May include surrounding context.

md
│   ├── service.yaml
│   ├── ingress.yaml
│   ├── configmap.yaml
│   ├── secret.yaml
│   ├── hpa.yaml
│   ├── pdb.yaml
│   ├── serviceaccount.yaml

Credential Access

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Requiring KUBECONFIG gives the orchestrator access to cluster credentials even though its role is supposed to be coordination-only. This violates least privilege and increases the impact of prompt injection, misuse, or accidental command execution under elevated cluster access.

Content

Scanner excerpt · skills/orchestrator/SKILL.md (reported line 25)May include surrounding context.

md
model_invocation: false
  requires:
    env:
      - KUBECONFIG
    binaries:
      - kubectl
    credentials:

Credential Access

High
Category
Privilege Escalation
Confidence
82% confidence
Finding

Referencing KUBECONFIG again in the credential definition reinforces that the orchestrator is expected to hold cluster access credentials. In the context of a non-operational coordinator, that unnecessary credential exposure materially increases risk.

Content

Scanner excerpt · skills/orchestrator/SKILL.md (reported line 29)May include surrounding context.

md
binaries:
      - kubectl
    credentials:
      - kubeconfig: "Cluster access via KUBECONFIG"
    optional_binaries:
      - oc
---

Credential Access

High
Category
Privilege Escalation
Confidence
82% confidence
Finding

Referencing KUBECONFIG again in the credential definition reinforces that the orchestrator is expected to hold cluster access credentials. In the context of a non-operational coordinator, that unnecessary credential exposure materially increases risk.

Content

Scanner excerpt · skills/orchestrator/SKILL.md (reported line 29)May include surrounding context.

md
binaries:
      - kubectl
    credentials:
      - kubeconfig: "Cluster access via KUBECONFIG"
    optional_binaries:
      - oc
---

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The orchestrator is described as coordination-only, but these instructions let it create branches, commit changes, push to origin, and open pull requests. That gives a routing agent direct repository mutation capability, enabling unauthorized code or workflow changes and making supply-chain abuse easier.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

Self-modifying the repository and opening GitHub pull requests is an unjustified capability for a coordination skill and creates a direct path to persistence or workflow tampering. Combined with broad 'git add -A' behavior, it could package unrelated or sensitive changes and publish them remotely.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 32)May include surrounding context.

md
model_invocation: false
  requires:
    env:
      - KUBECONFIG
    binaries:
      - kubectl
    credentials:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

md
model_invocation: false
  requires:
    env:
      - KUBECONFIG
    binaries:
      - kubectl
    credentials:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

md
model_invocation: false
  requires:
    env:
      - KUBECONFIG
    binaries:
      - kubectl
    credentials:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 60)May include surrounding context.

md
model_invocation: false
  requires:
    env:
      - KUBECONFIG
    binaries:
      - kubectl
    credentials:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skills/artifacts/SKILL.md (reported line 26)May include surrounding context.

md
model_invocation: false
  requires:
    env:
      - KUBECONFIG
    binaries:
      - kubectl
    credentials:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skills/artifacts/SKILL.md (reported line 30)May include surrounding context.

md
model_invocation: false
  requires:
    env:
      - KUBECONFIG
    binaries:
      - kubectl
    credentials:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skills/cluster-ops/SKILL.md (reported line 25)May include surrounding context.

md
model_invocation: false
  requires:
    env:
      - KUBECONFIG
    binaries:
      - kubectl
    credentials:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skills/cluster-ops/SKILL.md (reported line 29)May include surrounding context.

md
model_invocation: false
  requires:
    env:
      - KUBECONFIG
    binaries:
      - kubectl
    credentials:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skills/developer-experience/SKILL.md (reported line 26)May include surrounding context.

md
model_invocation: false
  requires:
    env:
      - KUBECONFIG
    binaries:
      - kubectl
    credentials:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skills/developer-experience/SKILL.md (reported line 30)May include surrounding context.

md
model_invocation: false
  requires:
    env:
      - KUBECONFIG
    binaries:
      - kubectl
    credentials:

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
skills/observability/SKILL.md:542