ZappushZappush
SkillsUse CasesBenchmarkCommunitySign In
      Back to Skills
      kcns008

      Safety Report

      Kubernetes

      @kcns008

      Complete Platform Agent Swarm — A coordinated multi-agent system for Kubernetes and OpenShift platform operations. Includes Orchestrator (Jarvis), Cluster Op...

      4,944Downloads
      34Installs
      4Stars
      2Versions
      DevOps & Infrastructure1,045

      Security Analysis

      medium confidence
      Suspicious0.08 risk

      The skill's description and instructions match a powerful Kubernetes multi-agent toolkit, but the package asks for no declared credentials or runtime requirements while containing many scripts that will expect kubeconfigs, cloud CLI credentials, and external integrations — this mismatch is concerning and needs clarification before install.

      Mar 3, 202650 files5 concerns
      Purpose & Capabilityconcern

      The skill legitimately targets cluster operations, GitOps, security, observability and artifact management and includes many helper scripts to do so. However, the registry metadata claims no required binaries, no environment variables, and no config paths, while SKILL.md and the included scripts clearly expect tools like kubectl/oc/helm/argocd/jq and access to kubeconfigs and cloud provider credentials (aws/az/gcloud/rosa). The lack of declared requirements/credentials is incoherent with the actual capabilities.

      Instruction Scopeconcern

      The runtime instructions and many scripts perform cluster reads and writes (kubectl/oc apply, argocd sync, image scans, etc.), generate and modify manifests, provision namespaces, run etcd backups, and instruct agents to read repository files (WORKING.md, LOGS.md, INCIDENTS.md) and git history. The SKILL.md also references external communication channels (Slack, Teams, PagerDuty) but does not declare how tokens/credentials are supplied. The session start protocol requires reading local files and git logs which can expose repository state and secrets if present. Overall the instruction scope goes beyond simple read-only guidance and enables actions that require privileged access.

      Install Mechanismnote

      There is no formal install spec in registry metadata (instruction-only), but SKILL.md suggests installing via npx pulling from a GitHub repo (github.com/kcns008/cluster-agent-swarm-skills). The repository contains many executable scripts that would be cloned/executed if the agent runs them. Cloning from a GitHub repo is common, but it means arbitrary scripts from that repo become available — review the repository before running. No downloads from obscure URLs are present in the metadata, but the 'npx skills add' pattern implicitly fetches code from an external source.

      Credentialsconcern

      The skill requests no environment variables or credentials in its manifest, yet the scripts and SKILL.md clearly require access to: kubeconfig (or a configured kubectl/oc), cloud provider credentials (AWS/Azure/GCP/ROSA), container registry credentials, and potentially credentials for Slack/Teams/PagerDuty/Vault. That mismatch is problematic: installing this skill without explicit credential declarations can lead to the agent accessing sensitive credentials available in the environment (e.g., ~/.kube/config, CLI default credentials) without the user being warned.

      Persistence & Privilegenote

      always: false (normal). The skill defines heartbeat schedules and persistent log/state files (logs/LOGS.md, memory/MEMORY.md) that agents are expected to read/write. Autonomous invocation is allowed (platform default) and would let the agent execute scripts against clusters. This is expected for an automation skill, but combined with the missing credential declarations it increases risk: an autonomously-invoking agent could act on any credentials available to the runtime environment.

      Guidance

      This package appears to be a comprehensive, high-privilege Kubernetes platform automation toolkit — which is fine if you trust the source and want that level of automation. Before installing: 1) Verify the GitHub source (kcns008) and review the repository contents yourself; 2) Do not install it into an environment with production kubeconfigs or cloud creds available to the agent process. Use a dedicated, least-privileged service account / kubeconfig for testing; 3) Confirm how Slack/Teams/PagerDuty/Vault integration is configured and where tokens would come from; 4) Prefer installing individual agent skills you need rather than the whole swarm; 5) If you must use the full swarm, require human approval for any destructive actions (ensure the platform enforces the declared guardrails), and run an audit/peer review of all scripts (especially anything that calls kubectl/oc, cloud CLIs, or manipulates secrets). If the maintainer can provide a manifest listing required binaries and explicit environment/credential requirements, re-run the evaluation — that would raise confidence toward benign.

      Latest Release

      v1.0.1

      **Major update: Skill transformed from a general Kubernetes guide to a modular, multi-agent system (Cluster Agent Swarm) for platform operations.** - Introduces a coordinated agent architecture, splitting functions into specialized agents: Orchestrator, Cluster Ops, GitOps, Security, Observability, Artifacts, and Developer Experience. - Adds documentation for all agents, detailed capability breakdowns, roles, communication protocols, heartbeats, and escalation flows. - New install instructions for both full swarm and individual agents. - Source reorganized: scripts and docs for platform tasks now distributed into agent-based folders by domain. - Expands supported platforms and tools (AKS, EKS, GKE, OpenShift, ROSA, ARO). - Previous monolithic scripts removed; replaced by modular, agent-scoped assets and documentation.

      More by @kcns008

      Cluster Agent Swarm

      0 stars

      self-improving-agent

      @pskoett · 1,456 stars

      Gog

      @steipete · 672 stars

      Tavily Web Search

      @arun-8687 · 620 stars

      Find Skills

      @JimLiuxinghai · 529 stars

      Proactive Agent

      @halthelobster · 426 stars

      Published by @kcns008 on ClawHub

      Zappush© 2026 Zappush
      HomeGuaranteeSupport

      Something feels unusual? We want to help: [email protected]