This pod-diagnosis skill has a coherent troubleshooting purpose, but it also ships and exposes many extra privileged cloud and Kubernetes actions that can reveal credentials/secrets or change infrastructure.
Install only after reviewing and constraining the dispatcher actions you are willing to expose. Use least-privilege Huawei IAM credentials, avoid passing AK/SK as command-line parameters, disable or remove kubeconfig/secret/export/mutation/subagent actions if you only need pod diagnosis, and treat logs, audit data, raw reports, and kubeconfig output as sensitive operational data.