Back to skill

Security audit

tencentcloud-tke-skill

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a legitimate Tencent Cloud Kubernetes operations skill, but it needs Review because it can expose or persist powerful cluster credentials and grants broad tenant access.

Install only in a trusted operator environment with tightly scoped Tencent Cloud and Kubernetes credentials. Avoid passing secrets on the command line, review the resolved kubeconfig and target cluster before use, shorten tenant token lifetimes, remove Secret access from default tenant roles unless explicitly needed, and prefer dry-run previews before endpoint, RBAC, kubeconfig, Helm, or delete operations.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
rbac_templates.yaml:8
Finding

Tenant RBAC Templates Grant Excessive Access to Secrets and Workload Execution

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
k8s_cli.py:98
Finding

Tencent Cloud Credentials Are Forwarded Through Process Command-Line Arguments

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
k8s_cli.py:316
Finding

Merged Kubeconfig Files Are Written Without Explicit Restrictive Permissions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
k8s_cli.py:534
Finding

Long-Lived Kubernetes Bearer Tokens Are Printed in Plaintext

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:27
Finding

Third-Party Cloud SDK Dependencies Are Installed Without Version or Hash Pinning

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (164)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The documented behavior includes infrastructure-changing operations such as creating/deleting cluster endpoints and retrieving kubeconfig, which materially expand cluster exposure and grant access credentials beyond what a generic ops description implies. This mismatch is dangerous because users may invoke the skill expecting observation/troubleshooting while it also enables access-enablement and credential retrieval that can compromise cluster boundaries.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The documented behavior includes infrastructure-changing operations such as creating/deleting cluster endpoints and retrieving kubeconfig, which materially expand cluster exposure and grant access credentials beyond what a generic ops description implies. This mismatch is dangerous because users may invoke the skill expecting observation/troubleshooting while it also enables access-enablement and credential retrieval that can compromise cluster boundaries.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 12)May include surrounding context.

md
- `k8s_cli.py` — Kubernetes 集群内操作(资源管理、Pod 操作、Helm 部署)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 622)May include surrounding context.

md
- `k8s_cli.py` — Kubernetes 集群内操作(资源管理、Pod 操作、Helm 部署)

Credential Access

High
Category
Privilege Escalation
Confidence
84% confidence
Finding

The documented kubeconfig resolution order shows automatic handling of cluster access credentials, including fetching them from TKE APIs and local files. In an agent context, automatic credential resolution increases the chance that powerful credentials are consumed without the operator fully understanding which identity or cluster will be used.

Content

Scanner excerpt · SKILL.md (reported line 21)May include surrounding context.

md
1. **环境变量**:`TENCENTCLOUD_SECRET_ID` / `TENCENTCLOUD_SECRET_KEY`
2. **命令行参数**:`--secret-id` / `--secret-key`

### Kubeconfig(k8s_cli.py 使用)
支持四级优先级(自动解析):
1. `--kubeconfig` 参数指定文件路径
2. `--cluster-id` + `--region` 自动从 TKE API 获取(显式指定集群时优先)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 25)May include surrounding context.

md
支持四级优先级(自动解析):
1. `--kubeconfig` 参数指定文件路径
2. `--cluster-id` + `--region` 自动从 TKE API 获取(显式指定集群时优先)
3. `KUBECONFIG` 环境变量
4. `~/.kube/config` 默认路径

## 前置依赖

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · k8s_cli.py (reported line 51)May include surrounding context.

python
支持四级优先级(自动解析):
1. `--kubeconfig` 参数指定文件路径
2. `--cluster-id` + `--region` 自动从 TKE API 获取(显式指定集群时优先)
3. `KUBECONFIG` 环境变量
4. `~/.kube/config` 默认路径

## 前置依赖

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · k8s_cli.py (reported line 70)May include surrounding context.

python
支持四级优先级(自动解析):
1. `--kubeconfig` 参数指定文件路径
2. `--cluster-id` + `--region` 自动从 TKE API 获取(显式指定集群时优先)
3. `KUBECONFIG` 环境变量
4. `~/.kube/config` 默认路径

## 前置依赖

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · k8s_cli.py (reported line 71)May include surrounding context.

python
支持四级优先级(自动解析):
1. `--kubeconfig` 参数指定文件路径
2. `--cluster-id` + `--region` 自动从 TKE API 获取(显式指定集群时优先)
3. `KUBECONFIG` 环境变量
4. `~/.kube/config` 默认路径

## 前置依赖

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · k8s_cli.py (reported line 83)May include surrounding context.

python
支持四级优先级(自动解析):
1. `--kubeconfig` 参数指定文件路径
2. `--cluster-id` + `--region` 自动从 TKE API 获取(显式指定集群时优先)
3. `KUBECONFIG` 环境变量
4. `~/.kube/config` 默认路径

## 前置依赖

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · k8s_cli.py (reported line 379)May include surrounding context.

python
支持四级优先级(自动解析):
1. `--kubeconfig` 参数指定文件路径
2. `--cluster-id` + `--region` 自动从 TKE API 获取(显式指定集群时优先)
3. `KUBECONFIG` 环境变量
4. `~/.kube/config` 默认路径

## 前置依赖

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · k8s_cli.py (reported line 381)May include surrounding context.

python
支持四级优先级(自动解析):
1. `--kubeconfig` 参数指定文件路径
2. `--cluster-id` + `--region` 自动从 TKE API 获取(显式指定集群时优先)
3. `KUBECONFIG` 环境变量
4. `~/.kube/config` 默认路径

## 前置依赖

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · k8s_cli.py (reported line 702)May include surrounding context.

python
支持四级优先级(自动解析):
1. `--kubeconfig` 参数指定文件路径
2. `--cluster-id` + `--region` 自动从 TKE API 获取(显式指定集群时优先)
3. `KUBECONFIG` 环境变量
4. `~/.kube/config` 默认路径

## 前置依赖

Credential Access

High
Category
Privilege Escalation
Confidence
84% confidence
Finding

The skill is explicitly designed to locate and use kubeconfig from standard sources such as explicit paths, environment variables, and ~/.kube/config. In this context, that is a credential-access capability: an agent using this skill can consume existing cluster credentials and act on behalf of the user across potentially sensitive environments.

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

md
1. `--kubeconfig` 参数指定文件路径
2. `--cluster-id` + `--region` 自动从 TKE API 获取(显式指定集群时优先)
3. `KUBECONFIG` 环境变量
4. `~/.kube/config` 默认路径

## 前置依赖

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The skill explicitly supports retrieving cluster kubeconfig, which directly yields access material to the Kubernetes API. In the context of an ops agent with Bash and Write access, this is highly sensitive because it enables follow-on cluster administration or credential redistribution.

Content

Scanner excerpt · SKILL.md (reported line 77)May include surrounding context.

python {baseDirectory}/tke_cli.py endpoint-status --region ap-guangzhou --cluster-id cls-xxx --is-extranet

text

### 6. kubeconfig - 获取集群 kubeconfig
```bash
python {baseDirectory}/tke_cli.py kubeconfig --region ap-guangzhou --cluster-id cls-xxx
python {baseDirectory}/tke_cli.py kubeconfig --region ap-guangzhou --cluster-id cls-xxx --is-extranet

Credential Access

High
Category
Privilege Escalation
Confidence
89% confidence
Finding

Automatically obtaining kubeconfig for TKE clusters as part of normal k8s_cli usage blurs the boundary between routine resource inspection and credential acquisition. This makes the skill more dangerous because simple cluster operations can implicitly trigger privileged credential fetching and subsequent high-impact actions.

Content

Scanner excerpt · SKILL.md (reported line 202)May include surrounding context.

python {baseDirectory}/k8s_cli.py -n [参数]

text

使用 TKE 集群时可自动获取 kubeconfig:
```bash
python {baseDirectory}/k8s_cli.py <command> --cluster-id cls-xxx --region ap-guangzhou -n <namespace> [参数]

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

Persistent kubeconfig context switching can redirect future authenticated actions to another cluster using stored credentials. In a shared or automated environment this can lead to mistakes or abuse, especially when combined with destructive commands available in the same skill.

Content

Scanner excerpt · SKILL.md (reported line 347)May include surrounding context.

16. context-use - 切换当前 context

注意:此命令会修改 kubeconfig 文件中的 current-context 字段。仅适用于持久化的 kubeconfig 文件(--kubeconfig / KUBECONFIG 环境变量 / ~/.kube/config),不适用于通过 --cluster-id 自动获取的临时 kubeconfig。

bash
python {baseDirectory}/k8s_cli.py context-use my-cluster-context

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

Persistent kubeconfig context switching can redirect future authenticated actions to another cluster using stored credentials. In a shared or automated environment this can lead to mistakes or abuse, especially when combined with destructive commands available in the same skill.

Content

Scanner excerpt · SKILL.md (reported line 347)May include surrounding context.

16. context-use - 切换当前 context

注意:此命令会修改 kubeconfig 文件中的 current-context 字段。仅适用于持久化的 kubeconfig 文件(--kubeconfig / KUBECONFIG 环境变量 / ~/.kube/config),不适用于通过 --cluster-id 自动获取的临时 kubeconfig。

bash
python {baseDirectory}/k8s_cli.py context-use my-cluster-context

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

Persistent kubeconfig context switching can redirect future authenticated actions to another cluster using stored credentials. In a shared or automated environment this can lead to mistakes or abuse, especially when combined with destructive commands available in the same skill.

Content

Scanner excerpt · SKILL.md (reported line 347)May include surrounding context.

16. context-use - 切换当前 context

注意:此命令会修改 kubeconfig 文件中的 current-context 字段。仅适用于持久化的 kubeconfig 文件(--kubeconfig / KUBECONFIG 环境变量 / ~/.kube/config),不适用于通过 --cluster-id 自动获取的临时 kubeconfig。

bash
python {baseDirectory}/k8s_cli.py context-use my-cluster-context

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The kubeconfig-add feature is a credential/configuration import pathway that can persist new trusted clusters, users, and auth methods into the operator's environment. This is dangerous because malicious or unsafe kubeconfig content can influence later authenticated actions and credential execution flows.

Content

Scanner excerpt · SKILL.md (reported line 360)May include surrounding context.

python {baseDirectory}/k8s_cli.py context-current --kubeconfig ~/.kube/config

text

#### 18. kubeconfig-add - 合并外部 kubeconfig

将外部 kubeconfig 文件合并到当前配置中,支持 --dry-run 预览。
目标文件优先级:--kubeconfig 参数 > KUBECONFIG 环境变量 > ~/.kube/config

Credential Access

High
Category
Privilege Escalation
Confidence
91% confidence
Finding

The kubeconfig-add capability imports external kubeconfig into the user's active configuration, potentially trusting unvetted cluster endpoints, certificate authorities, exec credential plugins, and contexts. This can introduce malicious or unintended credential flows, persist access to attacker-controlled clusters, or cause later commands to authenticate using imported settings.

Content

Scanner excerpt · SKILL.md (reported line 363)May include surrounding context.

18. kubeconfig-add - 合并外部 kubeconfig

将外部 kubeconfig 文件合并到当前配置中,支持 --dry-run 预览。 目标文件优先级:--kubeconfig 参数 > KUBECONFIG 环境变量 > ~/.kube/config

bash
# 预览合并结果(不写入)

Credential Access

High
Category
Privilege Escalation
Confidence
91% confidence
Finding

The kubeconfig-add capability imports external kubeconfig into the user's active configuration, potentially trusting unvetted cluster endpoints, certificate authorities, exec credential plugins, and contexts. This can introduce malicious or unintended credential flows, persist access to attacker-controlled clusters, or cause later commands to authenticate using imported settings.

Content

Scanner excerpt · SKILL.md (reported line 363)May include surrounding context.

18. kubeconfig-add - 合并外部 kubeconfig

将外部 kubeconfig 文件合并到当前配置中,支持 --dry-run 预览。 目标文件优先级:--kubeconfig 参数 > KUBECONFIG 环境变量 > ~/.kube/config

bash
# 预览合并结果(不写入)

Credential Access

High
Category
Privilege Escalation
Confidence
91% confidence
Finding

The kubeconfig-add capability imports external kubeconfig into the user's active configuration, potentially trusting unvetted cluster endpoints, certificate authorities, exec credential plugins, and contexts. This can introduce malicious or unintended credential flows, persist access to attacker-controlled clusters, or cause later commands to authenticate using imported settings.

Content

Scanner excerpt · SKILL.md (reported line 363)May include surrounding context.

18. kubeconfig-add - 合并外部 kubeconfig

将外部 kubeconfig 文件合并到当前配置中,支持 --dry-run 预览。 目标文件优先级:--kubeconfig 参数 > KUBECONFIG 环境变量 > ~/.kube/config

bash
# 预览合并结果(不写入)

Credential Access

High
Category
Privilege Escalation
Confidence
98% confidence
Finding

The prompt-generate command explicitly creates output containing kubeconfig and a tenant token for direct distribution. This is a credential exposure capability that can leak live cluster access to unintended recipients, logs, transcripts, or downstream systems, especially because the generated prompt is meant to be copy-pasted and shared.

Content

Scanner excerpt · SKILL.md (reported line 419)May include surrounding context.

23. prompt-generate - 为租户生成一键安装 Prompt

生成包含 kubeconfig + Token + 安装指引的完整 Prompt 文本,可直接发给租户用户。

bash
python {baseDirectory}/k8s_cli.py prompt-generate zhangsan -n team-a

Credential Access

High
Category
Privilege Escalation
Confidence
92% confidence
Finding

The workflow for enabling endpoints and then retrieving kubeconfig describes a full path from no access to active cluster credentials. In context, this makes the skill especially dangerous because it can both expose a cluster endpoint and obtain the credentials needed to use it.

Content

Scanner excerpt · SKILL.md (reported line 443)May include surrounding context.

md
1. `tke_cli.py endpoints --cluster-id cls-xxx` 查看是否已开启访问
2. 如未开启,使用 `tke_cli.py create-endpoint` 开启内网或外网访问
3. `tke_cli.py endpoint-status --cluster-id cls-xxx` 确认端点状态为 Created
4. `tke_cli.py kubeconfig --cluster-id cls-xxx` 获取 kubeconfig
5. 指引用户保存 kubeconfig 并配置 kubectl

### 应用部署流程

Static analysis

No suspicious patterns detected.