Back to skill

Security audit

K8s容器编排工具

Security checks for vulnerabilities and agentic risk

Overview

This Kubernetes review skill appears non-malicious, but it mixes read-only YAML review with broad command execution, kubeconfig use, file writing, and vague API integration language that deserves review before installation.

Install only if you want an agent to help review Kubernetes YAML and possibly run read-only kubectl inspection commands. Prefer using it with pasted manifests or exported YAML first, and only allow live-cluster access after checking the active kubeconfig context, namespace, and exact command being run. Be cautious with manifests or cluster output that may include Secrets or tokens, and do not provide generic API keys unless the publisher clarifies why they are needed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (11)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 87)May include surrounding context.

md
|---:|---:|---:|---:|
| content | string | 否 | 待审查的Kubernetes YAML清单内容,或 `kubectl get -o yaml` 输出 |
| resource_type | string | 否 | 资源类型,可选值: `deployment`/`statefulset`/`service`/`pod`/`all`,默认 `all` |
| namespace | string | 否 | 目标命名空间,默认从kubeconfig当前上下文读取 |
| check_level | string | 否 | 检查级别,可选值: `strict`/`standard`/`basic`,默认 `standard` |
| style | string | 否 | 输出风格, 参考 `references/style.md` |

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 266)May include surrounding context.

md
|---:|---:|---:|---:|
| content | string | 否 | 待审查的Kubernetes YAML清单内容,或 `kubectl get -o yaml` 输出 |
| resource_type | string | 否 | 资源类型,可选值: `deployment`/`statefulset`/`service`/`pod`/`all`,默认 `all` |
| namespace | string | 否 | 目标命名空间,默认从kubeconfig当前上下文读取 |
| check_level | string | 否 | 检查级别,可选值: `strict`/`standard`/`basic`,默认 `standard` |
| style | string | 否 | 输出风格, 参考 `references/style.md` |

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 278)May include surrounding context.

md
|---:|---:|---:|---:|
| content | string | 否 | 待审查的Kubernetes YAML清单内容,或 `kubectl get -o yaml` 输出 |
| resource_type | string | 否 | 资源类型,可选值: `deployment`/`statefulset`/`service`/`pod`/`all`,默认 `all` |
| namespace | string | 否 | 目标命名空间,默认从kubeconfig当前上下文读取 |
| check_level | string | 否 | 检查级别,可选值: `strict`/`standard`/`basic`,默认 `standard` |
| style | string | 否 | 输出风格, 参考 `references/style.md` |

Credential Access

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 278)May include surrounding context.

md
|:------|------:|:------|:------|
| LLM API | API | 必需 | 由Agent内置LLM提供 |
| kubectl | CLI | 推荐 | https://kubernetes.io/docs/tasks/tools/ |
| kubeconfig | 配置 | 推荐 | 集群管理员提供,`~/.kube/config` |

### API Key 配置
-

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The metadata presents a Kubernetes review skill, but the description expands into generic automation and workflow usage unrelated to static K8s analysis. Overbroad scope increases the chance of unintended invocation in contexts where command execution, file access, or other tooling could be triggered without the user's informed intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation language is broad and not tightly tied to Kubernetes-specific triggers, making accidental or overbroad invocation more likely. In an agent environment, vague trigger text can cause the skill to activate for general efficiency or automation requests, exposing local files, command execution, or cluster context unnecessarily.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The markdown presents broad capability statements without precise trigger constraints, so the skill's operational boundary is unclear. Unclear boundaries are risky because this skill includes powerful tools and could be selected inappropriately for tasks beyond safe static analysis.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill claims in one section that it only performs static YAML review, but elsewhere advertises execution, file handling, and broader automation behaviors. This mismatch can cause an agent or user to trust the skill as read-only when it may invoke tools like exec or interact with the local environment or connected cluster.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill advertises command execution while also discussing kubectl access and cluster review, but does not clearly warn that commands may run in the local environment or against a connected Kubernetes cluster. In this context, undocumented exec capability is especially dangerous because it can alter cluster state, read sensitive config, or expose credentials through command output.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The documentation says the skill supports file writing or write-adjacent file handling without warning users that local files may be modified. Even if intended for convenience, undocumented write capability can lead to accidental overwrites, persistence of sensitive data, or changes to deployment artifacts.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

Advertising external API integration for a skill whose stated purpose is static Kubernetes YAML review creates unnecessary ambiguity about data flow and possible outbound transmission. Users may provide manifests, configs, or cluster-derived data assuming local-only analysis when the skill suggests broader service integration.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.