Back to skill

Security audit

Kubernetes Skills

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward Kubernetes Velero backup skill, with powerful restore examples that users should run carefully.

Install this only where the agent is allowed to operate on the active Kubernetes context. Before restores or schedules, verify the target cluster, namespace mappings, backup name, included resources, and whether Secrets should be restored; protect Velero backup storage because it may contain credentials.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill provides restore commands that can modify or overwrite live Kubernetes resources, including secrets and namespace mappings, without any warning, prerequisite checks, or confirmation guidance. In an operational backup/DR skill, omission of safety guidance increases the chance of accidental destructive changes to production clusters during routine use.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.