T05 · Unauthorized Access and Privilege Escalation
- Location
rbac_templates.yaml:8- Finding
Tenant RBAC Templates Grant Excessive Access to Secrets and Workload Execution
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This appears to be a legitimate Tencent Cloud Kubernetes operations skill, but it needs Review because it can expose or persist powerful cluster credentials and grants broad tenant access.
Install only in a trusted operator environment with tightly scoped Tencent Cloud and Kubernetes credentials. Avoid passing secrets on the command line, review the resolved kubeconfig and target cluster before use, shorten tenant token lifetimes, remove Secret access from default tenant roles unless explicitly needed, and prefer dry-run previews before endpoint, RBAC, kubeconfig, Helm, or delete operations.
rbac_templates.yaml:8Tenant RBAC Templates Grant Excessive Access to Secrets and Workload Execution
k8s_cli.py:98Tencent Cloud Credentials Are Forwarded Through Process Command-Line Arguments
k8s_cli.py:316Merged Kubeconfig Files Are Written Without Explicit Restrictive Permissions
k8s_cli.py:534Long-Lived Kubernetes Bearer Tokens Are Printed in Plaintext
SKILL.md:27Third-Party Cloud SDK Dependencies Are Installed Without Version or Hash Pinning
The documented behavior includes infrastructure-changing operations such as creating/deleting cluster endpoints and retrieving kubeconfig, which materially expand cluster exposure and grant access credentials beyond what a generic ops description implies. This mismatch is dangerous because users may invoke the skill expecting observation/troubleshooting while it also enables access-enablement and credential retrieval that can compromise cluster boundaries.
The documented behavior includes infrastructure-changing operations such as creating/deleting cluster endpoints and retrieving kubeconfig, which materially expand cluster exposure and grant access credentials beyond what a generic ops description implies. This mismatch is dangerous because users may invoke the skill expecting observation/troubleshooting while it also enables access-enablement and credential retrieval that can compromise cluster boundaries.
Referenced artifact was not completely inspected
- `k8s_cli.py` — Kubernetes 集群内操作(资源管理、Pod 操作、Helm 部署)
Referenced artifact was not completely inspected
- `k8s_cli.py` — Kubernetes 集群内操作(资源管理、Pod 操作、Helm 部署)
The documented kubeconfig resolution order shows automatic handling of cluster access credentials, including fetching them from TKE APIs and local files. In an agent context, automatic credential resolution increases the chance that powerful credentials are consumed without the operator fully understanding which identity or cluster will be used.
1. **环境变量**:`TENCENTCLOUD_SECRET_ID` / `TENCENTCLOUD_SECRET_KEY`
2. **命令行参数**:`--secret-id` / `--secret-key`
### Kubeconfig(k8s_cli.py 使用)
支持四级优先级(自动解析):
1. `--kubeconfig` 参数指定文件路径
2. `--cluster-id` + `--region` 自动从 TKE API 获取(显式指定集群时优先)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
支持四级优先级(自动解析):
1. `--kubeconfig` 参数指定文件路径
2. `--cluster-id` + `--region` 自动从 TKE API 获取(显式指定集群时优先)
3. `KUBECONFIG` 环境变量
4. `~/.kube/config` 默认路径
## 前置依赖
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
支持四级优先级(自动解析):
1. `--kubeconfig` 参数指定文件路径
2. `--cluster-id` + `--region` 自动从 TKE API 获取(显式指定集群时优先)
3. `KUBECONFIG` 环境变量
4. `~/.kube/config` 默认路径
## 前置依赖
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
支持四级优先级(自动解析):
1. `--kubeconfig` 参数指定文件路径
2. `--cluster-id` + `--region` 自动从 TKE API 获取(显式指定集群时优先)
3. `KUBECONFIG` 环境变量
4. `~/.kube/config` 默认路径
## 前置依赖
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
支持四级优先级(自动解析):
1. `--kubeconfig` 参数指定文件路径
2. `--cluster-id` + `--region` 自动从 TKE API 获取(显式指定集群时优先)
3. `KUBECONFIG` 环境变量
4. `~/.kube/config` 默认路径
## 前置依赖
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
支持四级优先级(自动解析):
1. `--kubeconfig` 参数指定文件路径
2. `--cluster-id` + `--region` 自动从 TKE API 获取(显式指定集群时优先)
3. `KUBECONFIG` 环境变量
4. `~/.kube/config` 默认路径
## 前置依赖
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
支持四级优先级(自动解析):
1. `--kubeconfig` 参数指定文件路径
2. `--cluster-id` + `--region` 自动从 TKE API 获取(显式指定集群时优先)
3. `KUBECONFIG` 环境变量
4. `~/.kube/config` 默认路径
## 前置依赖
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
支持四级优先级(自动解析):
1. `--kubeconfig` 参数指定文件路径
2. `--cluster-id` + `--region` 自动从 TKE API 获取(显式指定集群时优先)
3. `KUBECONFIG` 环境变量
4. `~/.kube/config` 默认路径
## 前置依赖
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
支持四级优先级(自动解析):
1. `--kubeconfig` 参数指定文件路径
2. `--cluster-id` + `--region` 自动从 TKE API 获取(显式指定集群时优先)
3. `KUBECONFIG` 环境变量
4. `~/.kube/config` 默认路径
## 前置依赖
The skill is explicitly designed to locate and use kubeconfig from standard sources such as explicit paths, environment variables, and ~/.kube/config. In this context, that is a credential-access capability: an agent using this skill can consume existing cluster credentials and act on behalf of the user across potentially sensitive environments.
1. `--kubeconfig` 参数指定文件路径
2. `--cluster-id` + `--region` 自动从 TKE API 获取(显式指定集群时优先)
3. `KUBECONFIG` 环境变量
4. `~/.kube/config` 默认路径
## 前置依赖
The skill explicitly supports retrieving cluster kubeconfig, which directly yields access material to the Kubernetes API. In the context of an ops agent with Bash and Write access, this is highly sensitive because it enables follow-on cluster administration or credential redistribution.
python {baseDirectory}/tke_cli.py endpoint-status --region ap-guangzhou --cluster-id cls-xxx --is-extranet
### 6. kubeconfig - 获取集群 kubeconfig
```bash
python {baseDirectory}/tke_cli.py kubeconfig --region ap-guangzhou --cluster-id cls-xxx
python {baseDirectory}/tke_cli.py kubeconfig --region ap-guangzhou --cluster-id cls-xxx --is-extranet
Automatically obtaining kubeconfig for TKE clusters as part of normal k8s_cli usage blurs the boundary between routine resource inspection and credential acquisition. This makes the skill more dangerous because simple cluster operations can implicitly trigger privileged credential fetching and subsequent high-impact actions.
python {baseDirectory}/k8s_cli.py -n [参数]
使用 TKE 集群时可自动获取 kubeconfig:
```bash
python {baseDirectory}/k8s_cli.py <command> --cluster-id cls-xxx --region ap-guangzhou -n <namespace> [参数]
Persistent kubeconfig context switching can redirect future authenticated actions to another cluster using stored credentials. In a shared or automated environment this can lead to mistakes or abuse, especially when combined with destructive commands available in the same skill.
注意:此命令会修改 kubeconfig 文件中的 current-context 字段。仅适用于持久化的 kubeconfig 文件(--kubeconfig / KUBECONFIG 环境变量 / ~/.kube/config),不适用于通过 --cluster-id 自动获取的临时 kubeconfig。
python {baseDirectory}/k8s_cli.py context-use my-cluster-context
Persistent kubeconfig context switching can redirect future authenticated actions to another cluster using stored credentials. In a shared or automated environment this can lead to mistakes or abuse, especially when combined with destructive commands available in the same skill.
注意:此命令会修改 kubeconfig 文件中的 current-context 字段。仅适用于持久化的 kubeconfig 文件(--kubeconfig / KUBECONFIG 环境变量 / ~/.kube/config),不适用于通过 --cluster-id 自动获取的临时 kubeconfig。
python {baseDirectory}/k8s_cli.py context-use my-cluster-context
Persistent kubeconfig context switching can redirect future authenticated actions to another cluster using stored credentials. In a shared or automated environment this can lead to mistakes or abuse, especially when combined with destructive commands available in the same skill.
注意:此命令会修改 kubeconfig 文件中的 current-context 字段。仅适用于持久化的 kubeconfig 文件(--kubeconfig / KUBECONFIG 环境变量 / ~/.kube/config),不适用于通过 --cluster-id 自动获取的临时 kubeconfig。
python {baseDirectory}/k8s_cli.py context-use my-cluster-context
The kubeconfig-add feature is a credential/configuration import pathway that can persist new trusted clusters, users, and auth methods into the operator's environment. This is dangerous because malicious or unsafe kubeconfig content can influence later authenticated actions and credential execution flows.
python {baseDirectory}/k8s_cli.py context-current --kubeconfig ~/.kube/config
#### 18. kubeconfig-add - 合并外部 kubeconfig
将外部 kubeconfig 文件合并到当前配置中,支持 --dry-run 预览。
目标文件优先级:--kubeconfig 参数 > KUBECONFIG 环境变量 > ~/.kube/config
The kubeconfig-add capability imports external kubeconfig into the user's active configuration, potentially trusting unvetted cluster endpoints, certificate authorities, exec credential plugins, and contexts. This can introduce malicious or unintended credential flows, persist access to attacker-controlled clusters, or cause later commands to authenticate using imported settings.
将外部 kubeconfig 文件合并到当前配置中,支持 --dry-run 预览。 目标文件优先级:--kubeconfig 参数 > KUBECONFIG 环境变量 > ~/.kube/config
# 预览合并结果(不写入)
The kubeconfig-add capability imports external kubeconfig into the user's active configuration, potentially trusting unvetted cluster endpoints, certificate authorities, exec credential plugins, and contexts. This can introduce malicious or unintended credential flows, persist access to attacker-controlled clusters, or cause later commands to authenticate using imported settings.
将外部 kubeconfig 文件合并到当前配置中,支持 --dry-run 预览。 目标文件优先级:--kubeconfig 参数 > KUBECONFIG 环境变量 > ~/.kube/config
# 预览合并结果(不写入)
The kubeconfig-add capability imports external kubeconfig into the user's active configuration, potentially trusting unvetted cluster endpoints, certificate authorities, exec credential plugins, and contexts. This can introduce malicious or unintended credential flows, persist access to attacker-controlled clusters, or cause later commands to authenticate using imported settings.
将外部 kubeconfig 文件合并到当前配置中,支持 --dry-run 预览。 目标文件优先级:--kubeconfig 参数 > KUBECONFIG 环境变量 > ~/.kube/config
# 预览合并结果(不写入)
The prompt-generate command explicitly creates output containing kubeconfig and a tenant token for direct distribution. This is a credential exposure capability that can leak live cluster access to unintended recipients, logs, transcripts, or downstream systems, especially because the generated prompt is meant to be copy-pasted and shared.
生成包含 kubeconfig + Token + 安装指引的完整 Prompt 文本,可直接发给租户用户。
python {baseDirectory}/k8s_cli.py prompt-generate zhangsan -n team-a
The workflow for enabling endpoints and then retrieving kubeconfig describes a full path from no access to active cluster credentials. In context, this makes the skill especially dangerous because it can both expose a cluster endpoint and obtain the credentials needed to use it.
1. `tke_cli.py endpoints --cluster-id cls-xxx` 查看是否已开启访问
2. 如未开启,使用 `tke_cli.py create-endpoint` 开启内网或外网访问
3. `tke_cli.py endpoint-status --cluster-id cls-xxx` 确认端点状态为 Created
4. `tke_cli.py kubeconfig --cluster-id cls-xxx` 获取 kubeconfig
5. 指引用户保存 kubeconfig 并配置 kubectl
### 应用部署流程
No suspicious patterns detected.