# Build Safer mirrord Configurations

Kubernetes configuration files can be difficult to write and easy to misconfigure. This skill creates, validates, and explains focused mirrord configurations.

## Install

```bash
npx skillstore add metalbear-co/mirrord-config
```

## Metadata

- Status: approved
- Slug: metalbear-co-mirrord-config
- Version: 1.25
- Author version: 1.25
- Skillstore revision: r1
- Version status: invalid
- Tree hash: cb6c84112a89d4137641ed2138eddcd06987466cc7cc4844565a9ab8eecdde54
- Author: metalbear-co
- GitHub username: metalbear-co
- License: MIT
- Repository: https://github.com/metalbear-co/skills/tree/a0ad7ca50ffb241a1c4f9c6a05d17661d5d658a5/skills/mirrord-config
- Ref: bad9dafc37d1638cd29cb9bab06d5f8dbcd0f6c2
- Supported tools: Claude, Codex, Claude Code
- Audit status: complete
- Agent install advisory: confirmation\_required
- Manual install advisory: allowed
- Artifact signature: available
- Audit attestation: unavailable
- Human verification: not\_verified
- Risk factors: external\_commands, network, filesystem, env\_access
- Quality score: 76
- Public page: https://skillstore.pages.dev/skills/metalbear-co-mirrord-config
- Manifest: https://skillstore.pages.dev/api/skills/metalbear-co-mirrord-config/manifest

## Capabilities

- Generate valid mirrord configurations from a stated Kubernetes workflow.
- Validate configuration structure against the bundled mirrord schema.
- Explain environment, filesystem, network, and target settings.
- Fix invalid JSON and unsupported configuration keys.
- Identify risky or unnecessary settings and suggest narrower alternatives.

## Use Cases

- Create a Local Development Config: Describe a target pod, namespace, and required features to receive a minimal configuration for local development.
- Review an Existing Config: Paste a mirrord configuration to identify schema errors, unnecessary settings, and behavior that may surprise a development team.
- Explain Network and Filesystem Modes: Ask for a focused explanation of traffic handling, environment mirroring, or remote filesystem behavior before changing a configuration.

## Prompt Templates

### Beginner: Generate a Minimal Config

```
Create a minimal mirrord configuration for my local service. Target pod API_SERVER in namespace staging. Mirror environment variables only.
```

### Intermediate: Validate a Config

```
Review this mirrord configuration against the official schema. List errors first, then warnings, then a corrected configuration without adding speculative settings.
```

### Advanced: Tune Traffic Handling

```
Design a mirrord configuration for a staging service that mirrors incoming traffic on port 8080 and keeps unrelated traffic unchanged. Explain each setting.
```

### Expert: Reduce Configuration Risk

```
Audit this mirrord configuration for unnecessary environment, filesystem, and network access. Propose the smallest change set that preserves the requested workflow.
```

## Limitations

- It does not install mirrord or Kubernetes tools automatically.
- It cannot verify cluster access, permissions, or live resource names.
- It does not replace testing against the exact mirrord and cluster versions.
- It should not receive or reproduce secret values in configuration output.

## Best Practices

- State the target, namespace, and required behavior before generating a configuration.
- Prefer minimal settings and validate against the schema before use.
- Review environment, filesystem, and network access for least privilege.

## Anti Patterns

- Do not add settings to guess at an unexplained timeout or connection failure.
- Do not include credentials, private keys, or full environment values in prompts.
- Do not treat a generated configuration as proof of cluster access or runtime compatibility.

## Security Audit

- Audited at: 2026-09-29T21:32:10.244\+00:00
- Summary: All 400 static matches were reviewed against the source documentation and schema. They are false positives caused by configuration examples, schema descriptions, path names, URLs, and command examples rather than executable security behavior. No prompt injection, data-exfiltration intent, or net-new semantic finding was identified. Static review was capped at 400/624 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.

## Stats

- Views: 0
- Downloads: 2
- Favorites: 0
- Popularity score: 0
