Back to skill

Security audit

K8s容器编排工具

Security checks across malware telemetry and agentic risk

Overview

This Kubernetes review skill is mostly purpose-aligned, but it asks for broad execution and cluster-context access with unclear limits.

Use this skill only with explicit scope: provide specific manifests or explicitly authorize read-only kubectl inspection of a named context and namespace. Do not provide API keys unless the publisher documents the exact external service and token scope. Review output carefully before applying any suggested fixes or scripts to a live cluster.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The skill is presented as a Kubernetes review tool, but it also claims broad file handling, API integration, and command execution abilities. This scope expansion increases the chance the agent will invoke powerful capabilities beyond user expectations, enabling unnecessary access to local files, external services, or shell commands during a nominally static review task.

Context-Inappropriate Capability

Medium
Confidence
89% confidence
Finding
Declaring API key configuration and external service dependencies for a Kubernetes manifest review skill creates unnecessary secret-handling pathways. This can mislead an agent into requesting, reading, or propagating credentials that are not essential to the stated function, increasing the risk of credential exposure or over-privileged integrations.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
Advertising generic system command execution for a narrowly scoped review skill is dangerous because it normalizes shell access where static parsing should suffice. In agent environments, this can lead to execution of user-influenced commands or collection of sensitive host/cluster data unrelated to the requested analysis.

Intent-Code Divergence

Medium
Confidence
83% confidence
Finding
The skill says it only performs static YAML analysis, yet other sections instruct using kubectl, kubeconfig context, and live namespace access. This inconsistency is risky because users may assume offline-only behavior while the agent actually touches a live cluster context, potentially exposing metadata or acting with ambient credentials.

Vague Triggers

Medium
Confidence
81% confidence
Finding
The activation language is overly broad and overlaps with general productivity and automation requests rather than narrowly targeting Kubernetes review. In agent routing systems, this can cause the skill to trigger in unrelated contexts and expose tools like exec, grep, or file access where they are unnecessary.

Vague Triggers

Medium
Confidence
78% confidence
Finding
The repeated, vague core-function text does not define clear boundaries for when the skill should or should not be used. Ambiguous routing guidance increases the chance of accidental invocation in unrelated tasks, which matters more here because the skill advertises access to powerful tools and cluster-related context.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.