Back to skill

Security audit

Kubernetes Skills

Security checks for vulnerabilities and agentic risk

Overview

This Kubernetes multi-cluster skill is coherent and not malicious, but it needs review because it normalizes handling cluster credentials, secrets, and production-changing operations without enough guardrails.

Review before installing in environments with real cluster access. Only use it with least-privilege Kubernetes credentials, require explicit target-context confirmation before mutating operations, avoid copying secrets across trust boundaries, and treat any retrieved kubeconfig as a sensitive credential that should be redacted, protected, short-lived, and cleaned up when no longer needed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (17)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · CONTEXT-SWITCHING.md (reported line 7)May include surrounding context.

md
## Understanding Contexts

A kubeconfig context combines:
- **Cluster**: API server URL and CA certificate
- **User**: Authentication credentials
- **Namespace**: Default namespace (optional)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · CONTEXT-SWITCHING.md (reported line 47)May include surrounding context.

md
## Understanding Contexts

A kubeconfig context combines:
- **Cluster**: API server URL and CA certificate
- **User**: Authentication credentials
- **Namespace**: Default namespace (optional)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · CONTEXT-SWITCHING.md (reported line 48)May include surrounding context.

md
## Understanding Contexts

A kubeconfig context combines:
- **Cluster**: API server URL and CA certificate
- **User**: Authentication credentials
- **Namespace**: Default namespace (optional)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 19)May include surrounding context.

md
## Understanding Contexts

A kubeconfig context combines:
- **Cluster**: API server URL and CA certificate
- **User**: Authentication credentials
- **Namespace**: Default namespace (optional)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 169)May include surrounding context.

md
## Understanding Contexts

A kubeconfig context combines:
- **Cluster**: API server URL and CA certificate
- **User**: Authentication credentials
- **Namespace**: Default namespace (optional)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · CONTEXT-SWITCHING.md (reported line 114)May include surrounding context.

Access Control Per Context

Separate Kubeconfigs

bash
# Different files per environment

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · CONTEXT-SWITCHING.md (reported line 118)May include surrounding context.

bash
# Different files per environment
export KUBECONFIG=~/.kube/production.yaml
export KUBECONFIG=~/.kube/development.yaml

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · CONTEXT-SWITCHING.md (reported line 119)May include surrounding context.

bash
# Different files per environment
export KUBECONFIG=~/.kube/production.yaml
export KUBECONFIG=~/.kube/development.yaml

Credential Access

High
Category
Privilege Escalation
Confidence
72% confidence
Finding

Retrieving a workload cluster kubeconfig via Cluster API can expose highly privileged access material if mishandled, and the example immediately suggests using it to access the workload cluster. In a multi-cluster management skill, this is more sensitive because fetched kubeconfigs may grant broad administrative access across environments if stored, logged, or shared insecurely.

Content

Scanner excerpt · CONTEXT-SWITCHING.md (reported line 141)May include surrounding context.

md
# List CAPI-managed clusters
capi_clusters_list_tool(namespace="capi-system")

# Get workload cluster kubeconfig
kubeconfig = capi_cluster_kubeconfig_tool(
    name="workload-cluster-1",
    namespace="capi-system"

Credential Access

High
Category
Privilege Escalation
Confidence
72% confidence
Finding

The assignment of the returned kubeconfig to a variable reflects active retrieval of cluster access credentials, which carries real exposure risk if later printed, stored, or reused improperly. Because this skill is specifically about switching among many clusters, accidental credential spread or privilege escalation is more plausible than in generic documentation.

Content

Scanner excerpt · CONTEXT-SWITCHING.md (reported line 142)May include surrounding context.

md
capi_clusters_list_tool(namespace="capi-system")

# Get workload cluster kubeconfig
kubeconfig = capi_cluster_kubeconfig_tool(
    name="workload-cluster-1",
    namespace="capi-system"
)

Credential Access

High
Category
Privilege Escalation
Confidence
78% confidence
Finding

The instruction to save the kubeconfig to a file and add it to contexts encourages persistence of sensitive cluster credentials without mentioning access controls, expiration, or cleanup. That can leave privileged kubeconfigs on disk and broaden long-term access to workload clusters, especially dangerous in a multi-cluster admin workflow.

Content

Scanner excerpt · CONTEXT-SWITCHING.md (reported line 147)May include surrounding context.

namespace="capi-system" )

Use the kubeconfig to access workload cluster

(save to file, add to contexts)

text

Credential Access

High
Category
Privilege Escalation
Confidence
92% confidence
Finding

The skill explicitly advertises retrieval of a workload cluster kubeconfig, which is a credential-bearing artifact that can grant cluster access if mishandled. In a multi-cluster management skill, access tokens or client certs for workload clusters are especially sensitive because compromise can expand attacker reach across environments.

Content

Scanner excerpt · SKILL.md (reported line 85)May include surrounding context.

capi_cluster_get_tool(name="prod-cluster", namespace="capi-system")

text

### Get Workload Cluster Kubeconfig

capi_cluster_kubeconfig_tool(name="prod-cluster", namespace="capi-system")

text

Credential Access

High
Category
Privilege Escalation
Confidence
93% confidence
Finding

This line documents direct use of a tool that returns cluster kubeconfig material, creating a clear path to credential disclosure if the output is shown, stored, or transferred insecurely. Because the skill is intended for multi-cluster operations, leaked kubeconfigs could enable unauthorized movement between clusters or compromise production environments.

Content

Scanner excerpt · SKILL.md (reported line 87)May include surrounding context.

Get Workload Cluster Kubeconfig

text
capi_cluster_kubeconfig_tool(name="prod-cluster", namespace="capi-system")

Machine Management

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation presents cross-cluster secret synchronization as a normal workflow without any caution about secret sensitivity, destination validation, or environment boundaries. In a multi-cluster Kubernetes skill, this can normalize copying credentials between clusters and increase the chance of propagating production secrets into less trusted environments or the wrong target cluster.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The rolling deployment example performs sequential production changes across multiple clusters but omits any warning about production impact, approval gates, rollback planning, or confirmation before proceeding. In a context-switching skill, that omission is risky because it can encourage operators or agents to execute broad production changes quickly and across the wrong contexts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill includes scaling and deployment-oriented examples such as changing machine deployment replica counts and cluster-targeted Helm/GitOps actions without explicitly warning that these operations can alter live infrastructure or cause service disruption. In a multi-cluster context, this is more dangerous because the same action may accidentally be applied to production, amplifying operational impact.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The secret synchronization example demonstrates reading secrets from one cluster and applying them to another without any warning about secret exposure, least-privilege handling, or cross-environment propagation risks. This is dangerous because it normalizes copying sensitive credentials across trust boundaries, which can leak production secrets into less secure clusters or logs.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.