competition-k8s-control-plane

Fail

Audited by Snyk on Jun 20, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 0.80). 该技能要求检查并重现导致 Kubernetes Secret 暴露或被消费的控制平面操作,并要求包含 "live describes"、挂载/注入路径和被消费的 Secret 等信息,可能需要以原文形式展示 Secret 数据,从而存在凭据外泄风险。

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (high risk: 0.80). 该技能明确要求对 Kubernetes 控制平面执行和重现实际的 API 修改(创建/修改 ServiceAccount、Role/ClusterRoleBinding、Secrets、控制器对象等),会改变运行环境的状态并可能导致权限提升和持久化改动;虽未直接要求宿主机 sudo 或创建系统级用户,但仍构成高风险。

Issues (2)

W007
HIGH

Insecure credential handling detected in skill instructions.

W013
MEDIUM

Attempt to modify system services in skill instructions.

Audit Metadata
Risk Level
HIGH
Analyzed
Jun 20, 2026, 03:16 AM
Issues
2
Security Audit — snyk — competition-k8s-control-plane