Skills mirrord-temporal
๐Ÿ“ฆ

mirrord-temporal

v1.2 Content revision r1 High Risk โš™๏ธ External commands๐Ÿ“ Filesystem access

Configure Temporal Queue Splitting with mirrord

Temporal workers need precise task routing during local debugging, but manual Kubernetes configuration is easy to misconfigure. This skill generates resource guidance, filters, validation checks, and troubleshooting steps for mirrord Temporal splitting.

Supports: Claude Codex Code(CC)
โš ๏ธ 38 Poor

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "mirrord-temporal" from https://skillstore.io/skills/metalbear-co-mirrord-temporal.md and its manifest at https://skillstore.io/api/skills/metalbear-co-mirrord-temporal/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.

Your Agent should still show its plan and request any confirmation required by the security policy.

Agent-readable resources

Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.

Test it

Using "mirrord-temporal". Route workflows beginning with test-local- to my laptop.

Expected outcome:

A review-ready split configuration plan with a Temporal queue filter on workflow ID, a matching local target, namespace checks, and a warning that matching tasks are stolen from the deployed worker.

Using "mirrord-temporal". Connect my self-hosted Temporal frontend with private CA and mTLS.

Expected outcome:

A secret-backed connection plan requiring the CA certificate, client certificate, and client key together. It explains that TLS protects the operator connection to the frontend.

Using "mirrord-temporal". Tasks accumulate while I debug at a breakpoint.

Expected outcome:

A troubleshooting checklist covering max buffered tasks, filter overlap, drain timeout, worker visibility, and the operator and CLI version requirements.

Security Audit

High Risk
v1 โ€ข 9/29/2026 Open versioned report

The static matches are mostly false positives caused by Markdown backticks, shell examples, placeholder certificate names, and secret-reference documentation. The skill still presents operational risk because it permits broad cluster discovery and mentions agent-directed operator installation, which require explicit authorization and least-privilege controls.

4
Files scanned
604
Lines analyzed
0
Review items
0
False positives ignored

Confirmed security concerns (2)

High
Agent-Directed Cluster Installation
The skill tells an AI agent that it may start a trial and install the mirrord operator after user agreement. Installing an operator changes cluster state and can grant broad control-plane access, so the action requires explicit confirmation and least-privilege review.
The instruction explicitly describes starting a trial and installing an operator. The operational impact is clear, although it requires user agreement and refers to another skill for the procedure.
Medium
Broad Cluster Discovery
The discovery workflow queries namespaces, workloads, CRDs, resources across all namespaces, deployment YAML, and services. These read-only queries can expose cluster topology and configuration metadata, so output handling and RBAC scope require controls.
The referenced commands visibly inspect multiple cluster-wide resource types. They are read-only, but the breadth of metadata access creates a confidentiality and least-privilege concern.
Audited by: codex
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/metalbear-co-mirrord-temporal/audits/1?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/metalbear-co-mirrord-temporal/security.svg)](https://skillstore.io/skills/metalbear-co-mirrord-temporal?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/metalbear-co-mirrord-temporal?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/metalbear-co-mirrord-temporal/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/metalbear-co-mirrord-temporal.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA ยท BibTeX ยท CFF)

APA citation

metalbear-co. (2026). mirrord-temporal security audit report (audit version 1) [Author version 1.2]. Skillstore. https://skillstore.io/skills/metalbear-co-mirrord-temporal/audits/1

BibTeX citation

@techreport{metalbear-co-metalbear-co-mirrord-temporal-2026, author = {metalbear-co}, title = {mirrord-temporal security audit report (audit version 1)}, institution = {Skillstore}, year = {2026}, number = {1}, url = {https://skillstore.io/skills/metalbear-co-mirrord-temporal/audits/1}, note = {Author version 1.2} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "mirrord-temporal security audit report (audit version 1)" version: "1.2" type: report authors: - name: "metalbear-co" date-released: "2026-09-29" url: "https://skillstore.io/skills/metalbear-co-mirrord-temporal/audits/1" identifiers: - type: other value: "skillstore:metalbear-co-mirrord-temporal:audit:1" description: "Skillstore immutable audit report identifier"

Skillstore Score

Why this score Evidence Confidence: Medium
55
Architecture
85
Maintainability
87
Content
65
Community
83
Spec Compliance

What You Can Build

Prepare a local worker session

Generate the resources and filters needed to route selected Temporal workflows or activities to a developer workstation.

Configure a shared cluster

Plan operator settings, workload references, namespaces, secrets, and queue limits for a controlled team environment.

Diagnose task routing

Review versions, filters, environment sources, buffering, TLS settings, and queue status when a split behaves unexpectedly.

Try These Prompts

Start a basic split
Set up Temporal task queue splitting for my worker. Ask only for the required workload, namespace, queue, and frontend details.
Use a workflow filter
Route only Temporal workflows whose IDs start with test-local- to my local worker. Explain the filter and required resource references.
Connect Temporal Cloud
Configure Temporal Cloud with TLS and a Kubernetes Secret for the API key. Check namespaces, versions, and secret references before presenting the resources.
Diagnose advanced routing
Review this Temporal splitting design for filter overlap, jq payload matching, task buffering, drain behavior, TLS configuration, and operator compatibility. Identify risks and propose corrected resources.

Best Practices

  • Use Kubernetes Secret references for API keys and certificate material.
  • Test filters and generated resources in a non-production namespace first.
  • Review task ownership, buffering limits, drain behavior, and operator versions before starting a session.

Avoid

  • Do not place API keys, certificates, or private keys directly in generated YAML.
  • Do not use mirror mode or Kafka fields in a Temporal queue configuration.
  • Do not apply cluster changes automatically without explicit review and authorization.

Frequently Asked Questions

What does this skill configure?
It configures guidance for Temporal queue splitting with MirrordPropertyList, MirrordSplitConfig, mirrord filters, and Helm values.
Can it install the mirrord operator?
No. It can explain prerequisites and present commands, but cluster changes require separate explicit review and authorization.
How are credentials handled?
Credentials should remain in Kubernetes Secrets and be referenced with secretKeyRef. Do not paste secret values into prompts.
Can I route only test workflows?
Yes. Use a message filter on workflow ID or another supported task field, then review overlap and task ownership.
Does Temporal support mirror mode here?
No. Temporal splitting is steal-only, so a matching local worker receives the task instead of receiving a copy.
Why are tasks delayed during debugging?
The operator buffers matching tasks. Check max_buffered_tasks, filter overlap, drain settings, and the compatibility of the operator and CLI versions.

Developer Details

License

MIT

Author version

v1.2

Skillstore revision

r1

Version notice

The author-declared version is not valid SemVer.

Ref

bad9dafc37d1638cd29cb9bab06d5f8dbcd0f6c2

Maintenance freshness

9/30/2026

Usage

0 downloads ยท 0 views

File structure

๐Ÿ“„ README.md

๐Ÿ“ references/

๐Ÿ“„ temporal-property-list.md

๐Ÿ“„ temporal-split-config.md

๐Ÿ“„ SKILL.md

More from metalbear-co

View all
View all