T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:28- Finding
Audit Instructions Recommend Excessive Cluster-Admin Privileges
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill appears to be a legitimate Kubernetes RBAC audit helper, but it needs review because it treats cluster-admin credentials and unpinned third-party audit tools as acceptable for a read-oriented audit.
Install only if you are comfortable with a Review-level Kubernetes security tool. Run it with a dedicated, short-lived, read-only audit identity, not production cluster-admin credentials; pin and verify any third-party tools before use; and store generated reports in an approved location because they may reveal sensitive cluster structure and permissions.
SKILL.md:28Audit Instructions Recommend Excessive Cluster-Admin Privileges
SKILL.md:29Unpinned and Unverified Third-Party Security Tool Installation
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
verbs = rule.get('verbs', [])
if ('secrets' in resources or '*' in resources) and ('get' in verbs or 'list' in verbs or '*' in verbs):
if not name.startswith('system:'):
print(f'ClusterRole: {name} -> can access secrets (verbs: {verbs})')
"
# Find roles with pod/exec permissions (container escape risk)
Beyond the literal path, the use of kubeconfig indicates the skill depends on a credential source to access Kubernetes APIs. In a documentation skill, instructing an agent to consume credential material without guardrails is dangerous because kubeconfig files often embed or broker privileged authentication to clusters.
# Run all kubeaudit checks
kubeaudit all --kubeconfig ~/.kube/config
# Run specific RBAC-related checks
kubeaudit privesc # Check for allowPrivilegeEscalation
Beyond the literal path, the use of kubeconfig indicates the skill depends on a credential source to access Kubernetes APIs. In a documentation skill, instructing an agent to consume credential material without guardrails is dangerous because kubeconfig files often embed or broker privileged authentication to clusters.
# Run all kubeaudit checks
kubeaudit all --kubeconfig ~/.kube/config
# Run specific RBAC-related checks
kubeaudit privesc # Check for allowPrivilegeEscalation
This occurrence similarly signals credential use via kubeconfig during report generation. The danger is not the audit logic itself but that the skill normalizes direct credential consumption and artifact creation without any safeguards around secrets, context verification, or storage of sensitive results.
kubeaudit capabilities # Check for dangerous capabilities
kubeaudit all --kubeconfig ~/.kube/config -f json > kubeaudit-results.json
## Key Concepts
This occurrence similarly signals credential use via kubeconfig during report generation. The danger is not the audit logic itself but that the skill normalizes direct credential consumption and artifact creation without any safeguards around secrets, context verification, or storage of sensitive results.
kubeaudit capabilities # Check for dangerous capabilities
kubeaudit all --kubeconfig ~/.kube/config -f json > kubeaudit-results.json
## Key Concepts
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
from kubernetes import client, config
config.load_kube_config() # From ~/.kube/config
# or
config.load_incluster_config() # Inside a pod
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
from kubernetes import client, config
def load_kube_config(kubeconfig=None, context=None):
"""Load Kubernetes configuration."""
if kubeconfig:
config.load_kube_config(config_file=kubeconfig, context=context)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
from kubernetes import client, config
def load_kube_config(kubeconfig=None, context=None):
"""Load Kubernetes configuration."""
if kubeconfig:
config.load_kube_config(config_file=kubeconfig, context=context)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
from kubernetes import client, config
def load_kube_config(kubeconfig=None, context=None):
"""Load Kubernetes configuration."""
if kubeconfig:
config.load_kube_config(config_file=kubeconfig, context=context)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
from kubernetes import client, config
def load_kube_config(kubeconfig=None, context=None):
"""Load Kubernetes configuration."""
if kubeconfig:
config.load_kube_config(config_file=kubeconfig, context=context)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
from kubernetes import client, config
def load_kube_config(kubeconfig=None, context=None):
"""Load Kubernetes configuration."""
if kubeconfig:
config.load_kube_config(config_file=kubeconfig, context=context)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
def main():
parser = argparse.ArgumentParser(description="Kubernetes RBAC Audit Agent")
parser.add_argument("--kubeconfig", default=os.getenv("KUBECONFIG"))
parser.add_argument("--context", help="Kubernetes context to use")
parser.add_argument("--output", default="k8s_rbac_audit.json")
parser.add_argument("--action", choices=[
The skill contains executable shell pipelines and writes output files (for example DOT/PNG artifacts and JSON reports) but does not declare any tool restrictions or allowed-tools scope. In an agent setting, missing scope boundaries can let the skill operate with broader filesystem/environment access than intended, increasing the chance of credential exposure or unsafe writes when run automatically.
The manifest describes RBAC-focused auditing: roles, bindings, wildcard permissions, service account abuse, and privilege escalation paths. However, the code also enumerates pods cluster-wide to detect automounted service account tokens and privileged/root containers, which are broader workload security checks rather than RBAC configuration analysis.
Skill requests more permissions than appear necessary for its stated functionality. Review if elevated access is justified.
# Who can exec into pods
kubectl rbac-tool who-can create pods/exec
# Who can escalate privileges (bind/escalate verbs)
kubectl rbac-tool who-can bind clusterroles
kubectl rbac-tool who-can escalate clusterroles
No suspicious patterns detected.