Back to skill

Security audit

K8s Fta Skill

Security checks for vulnerabilities and agentic risk

Overview

This Kubernetes troubleshooting skill is broadly useful, but it can run and directly apply high-impact cluster repair commands with unclear approval boundaries.

Install only for users who intentionally want an agent to troubleshoot Kubernetes clusters and who can constrain it to a safe context. Before use, require explicit approval for every mutating command, verify the current cluster and namespace, avoid production/admin kubeconfigs by default, and reserve certificate or etcd-key checks for supervised administrator workflows.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:51
Finding

Unvalidated Values Are Interpolated into Shell Commands

Content
View full analysis
-n ``` ```bash kubectl port-forward 8080: -n ``` ```bash kubectl auth can-i --as= -n kubectl get role -n kubectl get clusterrole kubectl get rolebinding -n kubectl get clusterrolebinding ``` ```bash kubectl exec -it -n -- nslookup kubectl exec -it -n -- cat /etc/resolv.conf ``` ```bash kubectl logs -n kube-system kube-apiserver- ``` ```bash kubectl patch pod -n --type='json' -p='[{"op": "replace", "path": "/spec/containers/0/resources/limits/memory", "value": "2Gi"}]' kubectl delete pod -n kubectl patch svc -n --type='json' -p='[{"op": "replace", "path": "/spec/ports/0/targetPort", "value": 8080}]' ``` ### Technical Analysis The Skill instructs an Agent with shell access to substitute user-provided or dynamically discovered values directly into command strings. Parameters such as ``, ``, ``, ``, and resource names are not accompanied by validation, escaping, or safe argument-passing requirements. If the Agent constructs these commands through a shell, a malicious value containing command separators, command substitution, redirection, or other shell metacharacters could escape the intended argument and execute an additional local command. The risk is particularly significant for values copied from a troubleshooting request without validating them against Kubernetes naming rules. The Skill does not require: - Canonical validation of Kubernetes resource names and namespaces. - Strict validatio ...[truncated 1837 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:663
Finding

Contradictory Consent Rules Permit Unapproved Destructive Kubernetes Repairs

Content
View full analysis
-n --type='json' -p='[{"op": "replace", "path": "/spec/containers/0/resources/limits/memory", "value": "2Gi"}]' # Example: automatically restart a failed Pod kubectl delete pod -n # Example: automatically update a Service port kubectl patch svc -n --type='json' -p='[{"op": "replace", "path": "/spec/ports/0/targetPort", "value": 8080}]' ``` The concluding behavior at line 722 states: ```text For problems that can be repaired automatically, the Skill directly executes repair operations. ``` ### Technical Analysis The Skill defines two incompatible authorization policies. The safety section requires confirmation before a change, while the concluding instruction directs the Agent to execute repairs directly when it considers a problem automatically repairable. An Agent may give greater operational weight to the later and more specific instruction. As a result, it could execute `kubectl patch` or `kubectl delete` without obtaining explicit approval. The affected examples are not harmless diagnostics: they modify live Services, attempt to alter workload configuration, or delete Pods. The Skill also lacks a precise definition of which conditions are “automatically repairable,” who may authorize a repair, and what safeguards must precede execution. No mandatory dry run, context verification, backup, impact preview, maintenance-window check, or rollback v ...[truncated 2016 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (21)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The document states that modification operations require user confirmation, but later says the skill will directly execute automatic repair actions. This contradiction undermines operator expectations and can lead to unapproved state-changing actions such as patching or deleting resources, increasing the chance of outages or unintended configuration drift.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill documents access to local Kubernetes PKI certificate files and etcd client/server keys, which are among the most sensitive assets in a cluster. If an agent follows this guidance in an automated context, it could read, expose, or misuse credentials that enable full control-plane compromise or direct access to cluster state.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 558)May include surrounding context.

md
**分析输出**:
- 检查API Server状态
- 检查kubeconfig配置
- 检查网络连接
- 检查API Server日志

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 564)May include surrounding context.

md
**分析输出**:
- 检查API Server状态
- 检查kubeconfig配置
- 检查网络连接
- 检查API Server日志

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 603)May include surrounding context.

md
**分析输出**:
- 检查API Server状态
- 检查kubeconfig配置
- 检查网络连接
- 检查API Server日志

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The behavior description promises automated fixing early in the skill without an immediate warning that some fixes may be destructive or service-impacting. In a Kubernetes operations context, users may interpret troubleshooting as safe/read-only while the skill may later perform disruptive actions like restarts, deletions, or patches.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill is presented as a kubectl-based troubleshooting tool, but these sections expand into host-level administration and direct inspection of local PKI and etcd-related material. That broadens privilege requirements and can expose highly sensitive control-plane data or encourage execution on control-plane hosts, creating risk well beyond ordinary cluster diagnostics.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The examples include destructive operations such as deleting pods and patching live resources, but they do not clearly warn about user impact, rollout consequences, or possible downtime. Examples strongly shape agent behavior, so presenting these actions as routine can normalize unsafe remediation without proper safeguards.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This is a JSON manifest-style file, so vague-trigger checks apply. The prompts repeatedly use generic forms like "how to troubleshoot?" and similar Chinese equivalents without any explicit activation boundaries, exclusions, or narrower invocation rules, making the skill scope overly broad for many ordinary Kubernetes help requests.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
93% confidence
Finding

The expected behavior explicitly endorses automatic execution of kubectl commands and automatic fix recommendations without any stated confirmation, scope restriction, or safety gate. In a Kubernetes environment, even diagnostic commands can reveal sensitive cluster state, and automated remediation can lead to unauthorized or destructive changes if the skill is triggered in the wrong context.

Content

Scanner excerpt · evals/evals.json (reported line 13)May include surrounding context.

json
{
      "id": 2,
      "prompt": "My Pod keeps restarting with CrashLoopBackOff status, how to troubleshoot?",
      "expected_output": "Automatically execute kubectl get pods to identify abnormal Pod, run kubectl describe and kubectl logs commands to analyze the issue, and provide automatic fix recommendations",
      "files": []
    },
    {

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
93% confidence
Finding

This eval expects the skill to autonomously run service-inspection commands and provide automatic fix recommendations without human approval. In real deployments, such behavior can expose internal service topology and may lead the agent to modify networking or service configuration in ways that disrupt production workloads.

Content

Scanner excerpt · evals/evals.json (reported line 25)May include surrounding context.

json
{
      "id": 4,
      "prompt": "Service is created but cannot be accessed, how to troubleshoot?",
      "expected_output": "Automatically execute kubectl get svc and kubectl describe svc commands to check Service configuration, run kubectl get endpoints to check backend Pods, and provide automatic fix recommendations",
      "files": []
    },
    {

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
92% confidence
Finding

Automatically executing scheduling and node/resource inspection commands plus generating automatic fixes can drive the agent toward cluster-wide changes such as quota or capacity adjustments. In Kubernetes, those remediations can affect multi-tenant workloads and availability if taken without validation or authorization.

Content

Scanner excerpt · evals/evals.json (reported line 37)May include surrounding context.

json
{
      "id": 6,
      "prompt": "Pod is stuck in Pending status and cannot be scheduled, how to troubleshoot?",
      "expected_output": "Automatically execute kubectl describe pod, kubectl get resourcequota, and kubectl describe node commands to analyze resource issues, and provide automatic fix recommendations",
      "files": []
    },
    {

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
91% confidence
Finding

The eval encourages autonomous memory troubleshooting and automatic fix recommendations for OOMKilled Pods. Even if initial commands are read-only, automated fixes often involve changing resource limits/requests or restarting workloads, which can cause instability, higher costs, or reduced service quality when done without review.

Content

Scanner excerpt · evals/evals.json (reported line 49)May include surrounding context.

json
{
      "id": 8,
      "prompt": "Pod is OOMKilled, how to resolve?",
      "expected_output": "Automatically execute kubectl describe pod and kubectl top pod commands to check memory usage, analyze memory limit issues, and provide automatic fix recommendations",
      "files": []
    },
    {

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
91% confidence
Finding

Automatic analysis of liveness/readiness failures combined with automatic fix recommendations can lead to unsafe changes to health checks, rollout behavior, or container startup assumptions. Misapplied fixes may mask underlying faults or create cascading restarts in production environments.

Content

Scanner excerpt · evals/evals.json (reported line 61)May include surrounding context.

json
{
      "id": 10,
      "prompt": "Health check failures causing Pod restarts, how to troubleshoot?",
      "expected_output": "Automatically execute kubectl describe pod and kubectl logs commands to check health check configuration, analyze health check failure causes, and provide automatic fix recommendations",
      "files": []
    },
    {

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
95% confidence
Finding

RBAC troubleshooting is especially sensitive because automatic permission analysis and fix recommendations can encourage privilege expansion. In the Kubernetes context, over-broad role or rolebinding changes can quickly become privilege-escalation paths affecting the whole cluster.

Content

Scanner excerpt · evals/evals.json (reported line 73)May include surrounding context.

json
{
      "id": 12,
      "prompt": "RBAC permission denied errors, how to resolve?",
      "expected_output": "Automatically execute kubectl auth can-i, kubectl get role, and kubectl get rolebinding commands to check permission configuration, analyze permission issues, and provide automatic fix recommendations",
      "files": []
    },
    {

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
90% confidence
Finding

This eval expects automatic execution of kubectl exec for DNS troubleshooting, which crosses an important boundary by entering a running container. Exec-based diagnostics can expose in-container secrets, environment details, and application state, making autonomous execution riskier than simple metadata inspection.

Content

Scanner excerpt · evals/evals.json (reported line 85)May include surrounding context.

json
{
      "id": 14,
      "prompt": "Pod cannot resolve domain names, how to troubleshoot DNS issues?",
      "expected_output": "Automatically execute kubectl exec nslookup and kubectl get svc kube-dns commands to check DNS configuration, analyze DNS resolution issues, and provide automatic fix recommendations",
      "files": []
    },
    {

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
90% confidence
Finding

Autonomous HPA and metrics-server troubleshooting can lead to recommendations or actions that alter scaling behavior. Incorrect changes may create outages, runaway scaling, or cost spikes, especially in production clusters where autoscaling interacts with multiple workloads.

Content

Scanner excerpt · evals/evals.json (reported line 97)May include surrounding context.

json
{
      "id": 16,
      "prompt": "HPA auto-scaling not working, how to troubleshoot?",
      "expected_output": "Automatically execute kubectl get hpa, kubectl describe hpa, and kubectl get pods metrics-server commands to check HPA configuration, analyze scaling issues, and provide automatic fix recommendations",
      "files": []
    },
    {

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
92% confidence
Finding

The same autonomous execution pattern is present for k3s environments, where deployments are often lightweight, edge-hosted, or less segmented. That context can make unsupervised diagnostics and fixes more dangerous because the cluster may run with broader default privileges and fewer operational controls.

Content

Scanner excerpt · evals/evals.json (reported line 109)May include surrounding context.

json
{
      "id": 18,
      "prompt": "k3s cluster Pod in CrashLoopBackOff status, how to troubleshoot?",
      "expected_output": "Automatically execute kubectl get pods to identify abnormal Pod, run kubectl describe and kubectl logs commands to analyze the issue, and provide automatic fix recommendations (supports k3s)",
      "files": []
    },
    {

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
92% confidence
Finding

Automatic service troubleshooting and fix recommendations in k3s can expose internal networking state and may prompt networking changes without review. In small or edge clusters, a single mistaken fix can affect the entire environment due to reduced isolation and shared control-plane access.

Content

Scanner excerpt · evals/evals.json (reported line 121)May include surrounding context.

json
{
      "id": 20,
      "prompt": "k3s service cannot be accessed, how to troubleshoot?",
      "expected_output": "Automatically execute kubectl get svc and kubectl describe svc commands to check Service configuration, run kubectl get endpoints to check backend Pods, and provide automatic fix recommendations (supports k3s)",
      "files": []
    }
  ]

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

Natural-language policy checks apply to all file types. Including fixed Chinese and English variants is not inherently wrong, but the file does not indicate whether the skill adapts to the user's preferred language or offers language selection, which can create an implicit locale/language policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This JSON evaluation file hard-codes only Chinese and English natural-language queries as the accepted trigger examples, but provides no accompanying indication that the skill is intentionally limited to those languages or that users may choose their preferred language. Under the policy, forcing a specific language or locale without opt-in can be a natural-language policy concern even when expressed through example queries in config data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.