Back to skill

Security audit

Kubernetes RBAC Audit

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a legitimate Kubernetes RBAC audit helper, but it needs review because it treats cluster-admin credentials and unpinned third-party audit tools as acceptable for a read-oriented audit.

Install only if you are comfortable with a Review-level Kubernetes security tool. Run it with a dedicated, short-lived, read-only audit identity, not production cluster-admin credentials; pin and verify any third-party tools before use; and store generated reports in an approved location because they may reveal sensitive cluster structure and permissions.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:28
Finding

Audit Instructions Recommend Excessive Cluster-Admin Privileges

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:29
Finding

Unpinned and Unverified Third-Party Security Tool Installation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (15)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 82)May include surrounding context.

md
verbs = rule.get('verbs', [])
        if ('secrets' in resources or '*' in resources) and ('get' in verbs or 'list' in verbs or '*' in verbs):
            if not name.startswith('system:'):
                print(f'ClusterRole: {name} -> can access secrets (verbs: {verbs})')
"

# Find roles with pod/exec permissions (container escape risk)

Credential Access

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Beyond the literal path, the use of kubeconfig indicates the skill depends on a credential source to access Kubernetes APIs. In a documentation skill, instructing an agent to consume credential material without guardrails is dangerous because kubeconfig files often embed or broker privileged authentication to clusters.

Content

Scanner excerpt · SKILL.md (reported line 240)May include surrounding context.

bash
# Run all kubeaudit checks
kubeaudit all --kubeconfig ~/.kube/config

# Run specific RBAC-related checks
kubeaudit privesc    # Check for allowPrivilegeEscalation

Credential Access

High
Category
Privilege Escalation
Confidence
78% confidence
Finding

Beyond the literal path, the use of kubeconfig indicates the skill depends on a credential source to access Kubernetes APIs. In a documentation skill, instructing an agent to consume credential material without guardrails is dangerous because kubeconfig files often embed or broker privileged authentication to clusters.

Content

Scanner excerpt · SKILL.md (reported line 240)May include surrounding context.

bash
# Run all kubeaudit checks
kubeaudit all --kubeconfig ~/.kube/config

# Run specific RBAC-related checks
kubeaudit privesc    # Check for allowPrivilegeEscalation

Credential Access

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

This occurrence similarly signals credential use via kubeconfig during report generation. The danger is not the audit logic itself but that the skill normalizes direct credential consumption and artifact creation without any safeguards around secrets, context verification, or storage of sensitive results.

Content

Scanner excerpt · SKILL.md (reported line 249)May include surrounding context.

kubeaudit capabilities # Check for dangerous capabilities

Output as JSON for processing

kubeaudit all --kubeconfig ~/.kube/config -f json > kubeaudit-results.json

text

## Key Concepts

Credential Access

High
Category
Privilege Escalation
Confidence
78% confidence
Finding

This occurrence similarly signals credential use via kubeconfig during report generation. The danger is not the audit logic itself but that the skill normalizes direct credential consumption and artifact creation without any safeguards around secrets, context verification, or storage of sensitive results.

Content

Scanner excerpt · SKILL.md (reported line 249)May include surrounding context.

kubeaudit capabilities # Check for dangerous capabilities

Output as JSON for processing

kubeaudit all --kubeconfig ~/.kube/config -f json > kubeaudit-results.json

text

## Key Concepts

Credential Access

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/api-reference.md (reported line 10)May include surrounding context.

python
from kubernetes import client, config

config.load_kube_config()  # From ~/.kube/config
# or
config.load_incluster_config()  # Inside a pod

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/agent.py (reported line 12)May include surrounding context.

python
from kubernetes import client, config


def load_kube_config(kubeconfig=None, context=None):
    """Load Kubernetes configuration."""
    if kubeconfig:
        config.load_kube_config(config_file=kubeconfig, context=context)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/agent.py (reported line 14)May include surrounding context.

python
from kubernetes import client, config


def load_kube_config(kubeconfig=None, context=None):
    """Load Kubernetes configuration."""
    if kubeconfig:
        config.load_kube_config(config_file=kubeconfig, context=context)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/agent.py (reported line 15)May include surrounding context.

python
from kubernetes import client, config


def load_kube_config(kubeconfig=None, context=None):
    """Load Kubernetes configuration."""
    if kubeconfig:
        config.load_kube_config(config_file=kubeconfig, context=context)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/agent.py (reported line 142)May include surrounding context.

python
from kubernetes import client, config


def load_kube_config(kubeconfig=None, context=None):
    """Load Kubernetes configuration."""
    if kubeconfig:
        config.load_kube_config(config_file=kubeconfig, context=context)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/agent.py (reported line 151)May include surrounding context.

python
from kubernetes import client, config


def load_kube_config(kubeconfig=None, context=None):
    """Load Kubernetes configuration."""
    if kubeconfig:
        config.load_kube_config(config_file=kubeconfig, context=context)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/agent.py (reported line 142)May include surrounding context.

python
def main():
    parser = argparse.ArgumentParser(description="Kubernetes RBAC Audit Agent")
    parser.add_argument("--kubeconfig", default=os.getenv("KUBECONFIG"))
    parser.add_argument("--context", help="Kubernetes context to use")
    parser.add_argument("--output", default="k8s_rbac_audit.json")
    parser.add_argument("--action", choices=[

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill contains executable shell pipelines and writes output files (for example DOT/PNG artifacts and JSON reports) but does not declare any tool restrictions or allowed-tools scope. In an agent setting, missing scope boundaries can let the skill operate with broader filesystem/environment access than intended, increasing the chance of credential exposure or unsafe writes when run automatically.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest describes RBAC-focused auditing: roles, bindings, wildcard permissions, service account abuse, and privilege escalation paths. However, the code also enumerates pods cluster-wide to detect automounted service account tokens and privileged/root containers, which are broader workload security checks rather than RBAC configuration analysis.

Content

No source excerpt is available for this finding.

Excessive Permissions

Low
Category
Privilege Escalation
Confidence
80% confidence
Finding

Skill requests more permissions than appear necessary for its stated functionality. Review if elevated access is justified.

Content

Scanner excerpt · SKILL.md (reported line 154)May include surrounding context.

md
# Who can exec into pods
kubectl rbac-tool who-can create pods/exec

# Who can escalate privileges (bind/escalate verbs)
kubectl rbac-tool who-can bind clusterroles
kubectl rbac-tool who-can escalate clusterroles

Static analysis

No suspicious patterns detected.