Skills mirrord-temporal Audit History
📦

Audit History

mirrord-temporal - 1 audit

Sep 29, 2026, 10:08 PM

The static matches are mostly false positives caused by Markdown backticks, shell examples, placeholder certificate names, and secret-reference documentation. The skill still presents operational risk because it permits broad cluster discovery and mentions agent-directed operator installation, which require explicit authorization and least-privilege controls.

4
Files scanned
604
Lines analyzed
4
Review items
0
False positives ignored

Confirmed security concerns (2)

High
Agent-Directed Cluster Installation
The skill tells an AI agent that it may start a trial and install the mirrord operator after user agreement. Installing an operator changes cluster state and can grant broad control-plane access, so the action requires explicit confirmation and least-privilege review.
The instruction explicitly describes starting a trial and installing an operator. The operational impact is clear, although it requires user agreement and refers to another skill for the procedure.
Medium
Broad Cluster Discovery
The discovery workflow queries namespaces, workloads, CRDs, resources across all namespaces, deployment YAML, and services. These read-only queries can expose cluster topology and configuration metadata, so output handling and RBAC scope require controls.
The referenced commands visibly inspect multiple cluster-wide resource types. They are read-only, but the breadth of metadata access creates a confidentiality and least-privilege concern.
Audited by: codex