Back to skill

Security audit

deploy-k8s-cluster

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for Kubernetes deployment, but it asks for high-privilege SSH access and mixes test cleanup with possible full cluster destruction without enough safeguards.

Install only if you are comfortable giving the agent privileged access to dedicated Kubernetes hosts. Prefer SSH keys or an SSH agent over passwords, use throwaway or tightly scoped deployment accounts, back up or isolate target machines, and require explicit confirmation before any cleanup or destroy operation.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:84
Finding

Plaintext SSH Credential Collection Through Agent Conversation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 84–86 and 97–103
Vulnerability Type: Plaintext sensitive credential handling
Risk Level: Medium

Vulnerable Code Snippet

markdown
2. **SSH 访问方式**(二选一):
   - 方式 A:提供用户名和密码
   - 方式 B:提前配置好 SSH 信任关系(推荐)

The document then demonstrates submission of a plaintext credential:

markdown
**示例用户输入**:

有 3 台虚拟机:

  • 10.0.2.7 (Control Plane)
  • 10.0.2.8 (Worker)
  • 10.0.2.9 (Worker) SSH: worker/work@123 K8S 版本:官方最新版本(v1.35)
text

Technical Analysis

The Skill explicitly permits users to provide an SSH username and password directly to the AI Agent and reinforces that workflow with a plaintext password example. It provides no protected secret-input mechanism, credential-redaction requirement, retention policy, or prohibition against copying credentials into generated configuration, reports, logs, inventories, or Agent context.

Although SSH authentication is relevant to remote Kubernetes deployment, reusable passwords should not be submitted through ordinary conversational channels. Such content may be retained in conversation history, telemetry, execution context, or derived artifacts. Key-based SSH trust is only recommended, not required, and the document does not mandate short-lived or least-privilege credentials.

Attack Path

  1. The Agent loads the Skill and asks the user for an SSH access method.
  2. Following the documented option and example, the user submits a reusable SSH username and password in the conversation.
  3. The credential is retained in chat history, Agent context, telemetry, or a generated deployment artifact.
  4. An unauthorized party gains access to one of those records.
  5. The party extracts the credential and authenticates to the listed Kubernetes nodes.
  6. If the account has the elevated deployment permissions anticipated by the Skill, the party can modify hosts or compromise the cluster.

I

...[truncated 620 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove password submission through Agent conversations as a supported authentication method.
  2. Require preconfigured public-key authentication, an SSH agent, short-lived SSH certificates, or another ephemeral authentication mechanism.
  3. If passwords must be supported, collect them through a protected interactive prompt or approved secret manager that does not expose the value to chat history or logs.
  4. Require dedicated, time-limited deployment accounts with narrowly scoped sudo permissions instead of direct root access or broadly privileged reusable accounts.
  5. Explicitly prohibit credentials from being written to reports, inventories, configuration files, command-line arguments, telemetry, or logs.
  6. Add mandatory redaction rules for all command output and generated artifacts.
  7. Define credential rotation and revocation procedures following deployment.
  8. Replace the plaintext example with a non-secret placeholder such as SSH authentication: preconfigured SSH agent.
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest description and the entire operating guidance are written as mandatory Chinese-language instructions, with no indication that the skill can respond in the user's preferred language. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation unless the locale restriction is explicit and justified, which is not present here.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill documents M8 as a cleanup step for test resources, but elsewhere describes the same script as capable of full cluster destruction. In a root-level, remote-execution deployment skill, this ambiguity is dangerous because a user or agent may invoke cleanup expecting namespace/test cleanup and instead destroy the entire Kubernetes cluster and related state.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.