k8s-service-path
Warn
Audited by Socket on Aug 6, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
Purpose and actions are coherent for Kubernetes troubleshooting, and the skill text itself is read-only with no direct malicious behavior. The main issue is trust: it relies on a third-party `k8s-mcp` binary whose exact provenance is unclear, and that binary may operate with kubeconfig-backed cluster credentials, so this should be treated as suspicious high supply-chain risk rather than benign.
Confidence: 84%Severity: 82%
Audit Metadata