T09 · Insecure Skill Coding Practices
- Location
skills/orchestrator/SKILL.md:564- Finding
Mandatory Repository-Wide Git Staging Can Commit Sensitive and Unrelated Files
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This instruction-only Kubernetes operations skill is purpose-aligned overall, but it gives agents broad cluster and repository authority with several under-scoped ways to persist or disclose sensitive operational data.
Install only in a controlled operations environment after narrowing kubeconfig and cloud permissions, disabling or rewriting the git add -A commit and auto-PR workflows, adding strict redaction rules for logs and alerts, and requiring explicit approval for upgrades, secret reads, and external incident transmissions.
skills/orchestrator/SKILL.md:564Mandatory Repository-Wide Git Staging Can Commit Sensitive and Unrelated Files
skills/cluster-ops/SKILL.md:272Cloud and Cluster Credential Commands Print Sensitive Values into Agent-Visible Output
skills/gitops/SKILL.md:728Secret Creation Examples Pass Plaintext Passwords Through Command-Line Arguments
skills/orchestrator/SKILL.md:775Timeout-Based PagerDuty Escalation Can Disclose Cluster and Incident Data Without Per-Transmission Approval
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
- AZURE_TENANT_ID
- GOOGLE_APPLICATION_CREDENTIALS
credentials:
- kubeconfig: "KUBECONFIG path or ~/.kube/config for cluster access"
- cloud: "Optional cloud provider credentials for managed clusters (AWS/Azure/GCP)"
- registry: "Optional container registry credentials for image operations"
---
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
- AZURE_TENANT_ID
- GOOGLE_APPLICATION_CREDENTIALS
credentials:
- kubeconfig: "KUBECONFIG path or ~/.kube/config for cluster access"
- cloud: "Optional cloud provider credentials for managed clusters (AWS/Azure/GCP)"
- registry: "Optional container registry credentials for image operations"
---
AKS upgrade commands are high-impact control-plane and node changes, yet the section lacks an explicit warning or approval requirement. In a cluster-operations skill, these commands are contextually plausible, but that same plausibility makes unsafe autonomous execution more dangerous because upgrades can cause outages, incompatibilities, or irreversible drift.
The GKE upgrade section documents master and node-pool upgrades without an explicit warning despite their high operational risk. Such commands can impact production availability and compatibility, and the lack of execution safeguards encourages unsafe use by agents or operators following the instructions verbatim.
ARO upgrades are high-impact cluster mutations, but the section does not warn users to obtain approval first. In this operational context, missing guardrails materially increase the risk of service disruption because an agent may treat the examples as standard procedure and execute them prematurely.
Calling kubeconfig 'cluster access credentials' without a security warning normalizes distribution of highly sensitive access material. If operators follow this guidance casually, leaked or improperly stored kubeconfigs could provide unauthorized cluster access and lateral movement opportunities.
2. **Set up RBAC** — team gets edit role in their namespaces
3. **Create pull secrets** — for container registry access
4. **Create ArgoCD project** — limit which clusters/namespaces team can deploy to
5. **Generate kubeconfig** — cluster access credentials
6. **Share documentation** — platform guides, examples, runbooks
### Platform Documentation Topics
Calling kubeconfig 'cluster access credentials' without a security warning normalizes distribution of highly sensitive access material. If operators follow this guidance casually, leaked or improperly stored kubeconfigs could provide unauthorized cluster access and lateral movement opportunities.
2. **Set up RBAC** — team gets edit role in their namespaces
3. **Create pull secrets** — for container registry access
4. **Create ArgoCD project** — limit which clusters/namespaces team can deploy to
5. **Generate kubeconfig** — cluster access credentials
6. **Share documentation** — platform guides, examples, runbooks
### Platform Documentation Topics
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
│ ├── service.yaml
│ ├── ingress.yaml
│ ├── configmap.yaml
│ ├── secret.yaml
│ ├── hpa.yaml
│ ├── pdb.yaml
│ ├── serviceaccount.yaml
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
│ ├── service.yaml
│ ├── ingress.yaml
│ ├── configmap.yaml
│ ├── secret.yaml
│ ├── hpa.yaml
│ ├── pdb.yaml
│ ├── serviceaccount.yaml
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
│ ├── service.yaml
│ ├── ingress.yaml
│ ├── configmap.yaml
│ ├── secret.yaml
│ ├── hpa.yaml
│ ├── pdb.yaml
│ ├── serviceaccount.yaml
Requiring KUBECONFIG gives the orchestrator access to cluster credentials even though its role is supposed to be coordination-only. This violates least privilege and increases the impact of prompt injection, misuse, or accidental command execution under elevated cluster access.
model_invocation: false
requires:
env:
- KUBECONFIG
binaries:
- kubectl
credentials:
Referencing KUBECONFIG again in the credential definition reinforces that the orchestrator is expected to hold cluster access credentials. In the context of a non-operational coordinator, that unnecessary credential exposure materially increases risk.
binaries:
- kubectl
credentials:
- kubeconfig: "Cluster access via KUBECONFIG"
optional_binaries:
- oc
---
Referencing KUBECONFIG again in the credential definition reinforces that the orchestrator is expected to hold cluster access credentials. In the context of a non-operational coordinator, that unnecessary credential exposure materially increases risk.
binaries:
- kubectl
credentials:
- kubeconfig: "Cluster access via KUBECONFIG"
optional_binaries:
- oc
---
The orchestrator is described as coordination-only, but these instructions let it create branches, commit changes, push to origin, and open pull requests. That gives a routing agent direct repository mutation capability, enabling unauthorized code or workflow changes and making supply-chain abuse easier.
Self-modifying the repository and opening GitHub pull requests is an unjustified capability for a coordination skill and creates a direct path to persistence or workflow tampering. Combined with broad 'git add -A' behavior, it could package unrelated or sensitive changes and publish them remotely.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
model_invocation: false
requires:
env:
- KUBECONFIG
binaries:
- kubectl
credentials:
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
model_invocation: false
requires:
env:
- KUBECONFIG
binaries:
- kubectl
credentials:
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
model_invocation: false
requires:
env:
- KUBECONFIG
binaries:
- kubectl
credentials:
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
model_invocation: false
requires:
env:
- KUBECONFIG
binaries:
- kubectl
credentials:
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
model_invocation: false
requires:
env:
- KUBECONFIG
binaries:
- kubectl
credentials:
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
model_invocation: false
requires:
env:
- KUBECONFIG
binaries:
- kubectl
credentials:
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
model_invocation: false
requires:
env:
- KUBECONFIG
binaries:
- kubectl
credentials:
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
model_invocation: false
requires:
env:
- KUBECONFIG
binaries:
- kubectl
credentials:
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
model_invocation: false
requires:
env:
- KUBECONFIG
binaries:
- kubectl
credentials:
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
model_invocation: false
requires:
env:
- KUBECONFIG
binaries:
- kubectl
credentials:
Detected: suspicious.exposed_secret_literal