Skills mirrord-ci
๐Ÿ“ฆ

mirrord-ci

v1.4 Content revision r1 High Risk โš™๏ธ External commands๐ŸŒ Network access๐Ÿ“ Filesystem access๐Ÿ”‘ Env variables

Configure mirrord CI Tests for Kubernetes

Integration tests often require access to services already running in Kubernetes. This skill guides mirrord CI setup with platform-specific workflows, configuration validation, and session cleanup.

Supports: Claude Codex Code(CC)
โš ๏ธ 38 Poor

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "mirrord-ci" from https://skillstore.io/skills/metalbear-co-mirrord-ci.md and its manifest at https://skillstore.io/api/skills/metalbear-co-mirrord-ci/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.

Your Agent should still show its plan and request any confirmation required by the security policy.

Agent-readable resources

Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.

Test it

Using "mirrord-ci". Plan a GitHub Actions integration test job for our staging API.

Expected outcome:

  • Prerequisites: confirm the mirrord version, Operator entitlement, runner connectivity, and dedicated staging credentials.
  • Workflow: check out the application, configure authentication, start the target session, and run integration tests.
  • Cleanup: stop the session regardless of test success.
  • Safety review: confirm test data isolation and prevent untrusted changes from receiving cluster credentials.

Using "mirrord-ci". Our Next.js application behaves differently when CI connects through mirrord.

Expected outcome:

  • Check whether remote environment values conflict with the local Next.js or Nx runtime.
  • Review NODE_ENV and NX_NEXT_DIR without printing secret values.
  • Propose targeted environment exclusions and validate the resulting mirrord configuration before another test run.

Using "mirrord-ci". Certificate errors appeared after moving tests to a macOS runner.

Expected outcome:

  • Compare the runner trust store with the container certificate chain.
  • Configure approved trust roots instead of accepting every certificate.
  • Treat any temporary certificate bypass as a security exception requiring explicit approval.

Security Audit

High Risk
v1 โ€ข 9/29/2026 Open versioned report

Of 400 supplied alerts, 399 concern documentation or intended CI operations; signature removal presents a genuine integrity risk. Four semantic findings cover certificate bypass, privileged containers, cluster-wide network changes, and unsupported isolation assurances. No evidence found of prompt injection or covert exfiltration; two omitted static matches still require manual review. Static review was capped at 400/402 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.

4
Files scanned
4,165
Lines analyzed
1
Review items
0
False positives ignored

Confirmed security concerns (4)

High
Troubleshooting Recommends Disabling Certificate Validation
The guidance recommends "trust_any_certificate": true for certificate errors and states that every certificate becomes trusted. This can expose application connections to server impersonation and interception.
The troubleshooting example explicitly enables universal certificate trust without limiting it to an isolated diagnostic session or requiring restoration.
High
Permission Troubleshooting Broadens Container Privileges
The instructions recommend "privileged": true for permission or DNS failures. Privileged agents weaken container isolation and can expose the host when compromised.
The advice directly enables privileged execution without requiring administrator approval or evaluating narrower permissions. Actual exposure depends on deployment policy.
Medium
CI Troubleshooting Changes Cluster-Wide Networking
The Cilium workaround upgrades the release in kube-system and restarts its DaemonSet. Applying it without administrator review can disrupt networking for unrelated workloads.
The commands directly change cluster networking infrastructure, but the surrounding instructions provide no change approval, maintenance window, or rollback requirement.
Medium
Isolation Assurance Omits Shared Dependency Side Effects
The skill promises isolated execution without workload interference, but its examples connect directly to shared services without configuring database or traffic isolation. Tests can therefore modify shared data or trigger downstream effects.
The unconditional assurance exceeds the protections configured in the examples. The schema documents outbound traffic tunneling, which does not itself isolate dependency writes.
Capability review items (1)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

High
sudo privilege escalation
`sudo codesign --remove-signature ./<your-binary>`
The command uses sudo to remove a copied binary's signature for SIP troubleshooting. This weakens binary integrity protections despite its legitimate compatibility purpose.

Risk Factors

โš™๏ธ External commands (50)
๐ŸŒ Network access (47)
๐Ÿ“ Filesystem access (30)
๐Ÿ”‘ Env variables (11)
Audited by: codex
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/metalbear-co-mirrord-ci/audits/1?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/metalbear-co-mirrord-ci/security.svg)](https://skillstore.io/skills/metalbear-co-mirrord-ci?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/metalbear-co-mirrord-ci?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/metalbear-co-mirrord-ci/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/metalbear-co-mirrord-ci.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA ยท BibTeX ยท CFF)

APA citation

metalbear-co. (2026). mirrord-ci security audit report (audit version 1) [Author version 1.4]. Skillstore. https://skillstore.io/skills/metalbear-co-mirrord-ci/audits/1

BibTeX citation

@techreport{metalbear-co-metalbear-co-mirrord-ci-2026, author = {metalbear-co}, title = {mirrord-ci security audit report (audit version 1)}, institution = {Skillstore}, year = {2026}, number = {1}, url = {https://skillstore.io/skills/metalbear-co-mirrord-ci/audits/1}, note = {Author version 1.4} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "mirrord-ci security audit report (audit version 1)" version: "1.4" type: report authors: - name: "metalbear-co" date-released: "2026-09-29" url: "https://skillstore.io/skills/metalbear-co-mirrord-ci/audits/1" identifiers: - type: other value: "skillstore:metalbear-co-mirrord-ci:audit:1" description: "Skillstore immutable audit report identifier"

Skillstore Score

Why this score Evidence Confidence: Medium
55
Architecture
85
Maintainability
87
Content
65
Community
91
Spec Compliance

What You Can Build

Add Staging Integration Tests

Create a GitHub Actions workflow that starts an application with mirrord, runs integration tests, and stops sessions after failures.

Standardize CI Cluster Access

Adapt authentication, namespace permissions, secret references, and cleanup hooks for the CI platforms used across a team.

Diagnose Failed Test Sessions

Investigate missing traffic, environment conflicts, linking issues, or log locations before making changes to shared infrastructure.

Try These Prompts

Check Readiness
Help me prepare mirrord CI for [CI platform]. Ask about my Kubernetes target, CLI version, cluster access, and licensing before suggesting changes.
Create a CI Workflow
Create a [CI platform] workflow for deployment [name] in namespace [namespace]. Use [application command] and [test command], secret references, approved installation, and cleanup after failures.
Investigate a Failed Session
Diagnose this mirrord CI failure using sanitized logs: [logs]. Check target selection, runtime compatibility, environment filters, and port mapping. Ask before changing cluster settings.
Review Shared Cluster Safety
Review [workflow] and [mirrord configuration] for shared staging use. Assess permissions, traffic filters, dependency writes, secret exposure, and cleanup. Validate proposed configuration and require approval for security exceptions.

Best Practices

  • Use approved, pinned tooling and restrict cluster credentials to trusted jobs with the minimum required permissions.
  • Validate mirrord configuration and verify traffic and data isolation before testing against shared services.
  • Always stop sessions after tests and require explicit approval for privilege, certificate, or cluster networking changes.

Avoid

  • Giving untrusted pull request code access to shared cluster credentials or Enterprise API keys.
  • Treating mirrord connectivity as automatic isolation from shared database writes and external side effects.
  • Copying privileged mode, certificate bypass, or cluster networking workarounds into routine CI without review.

Frequently Asked Questions

Which AI tools can use this skill?
The skill supports Claude, Codex, and Claude Code.
Which CI platforms have examples?
The source includes GitHub Actions, GitLab CI, CircleCI, and Jenkins examples.
What must already be available?
The guide requires mirrord CLI 3.181.0 or later, Kubernetes access, kubeconfig, and a licensed Operator. Confirm current entitlement requirements before implementation.
How should CI secrets be handled?
Use your CI secret store for Kubernetes credentials and the Enterprise CI API key. Restrict access to trusted jobs and avoid logging values.
Does mirrord guarantee isolated tests?
No. Configure traffic selection and test data isolation explicitly, because application requests can still affect shared services.
Are all troubleshooting suggestions safe defaults?
No. Certificate bypass, privileged containers, signature removal, and cluster networking changes require security review and explicit approval.

Developer Details

License

MIT

Author version

v1.4

Skillstore revision

r1

Version notice

The author-declared version is not valid SemVer.

Ref

bad9dafc37d1638cd29cb9bab06d5f8dbcd0f6c2

Maintenance freshness

9/30/2026

Usage

0 downloads ยท 0 views

File structure

๐Ÿ“„ README.md

๐Ÿ“ references/

๐Ÿ“„ schema.json

๐Ÿ“„ troubleshooting.md

๐Ÿ“„ SKILL.md

More from metalbear-co

View all
View all