Hunt K8S
ListedHunt K8S — provides AI agent assistance for software development workflows.
Install on your platform
Showing Claude Code. One command installs this skill into any of the agents below.
- 1
Run this in your project
terminal$ npx skills add elementalsouls/claude-bughunter --skill hunt-k8s -a claude-code Uses the open-source
skillsCLI and needs Node.js. Add-gto install it for your user instead of this project.
What we know about this skill
Publisher
elementalsouls
Taken from the source listing. We haven't verified who controls this account.
Install target
Live repository
Not pinned. Installing fetches whatever the repository holds at the time you run the command.
Automated safety checks
This skill failed 3 of 6 checks. A failure is not proof of bad intent; it means something in the code needs a human to look at it before you run it.
No undeclared network calls: failed
Contacts 1 host that is neither well-known infrastructure nor declared in the skill's frontmatter: 169.254.169.254.
Every host the skill dials — from its scripts, its config endpoints or the commands it tells the agent to run — is either well-known package and API infrastructure or declared in its own frontmatter. Links in documentation are not counted.
Hosts contacted
169.254.169.254undeclaredmetadata.google.internallocalWhat it found (3 of 4)
- skills/hunt-k8s/SKILL.md:51contacts 169.254.169.254
curl -s "http://169.254.169.254/latest/meta-data/iam/security-credentials/" # AWS EKS (IMDSv1) - skills/hunt-k8s/SKILL.md:52contacts 169.254.169.254
TOK=$(curl -s -X PUT "http://169.254.169.254/latest/api/token" -H "X-aws-ec2-metadata-token-ttl-seconds: 60") # IMDSv2 - skills/hunt-k8s/SKILL.md:53contacts 169.254.169.254
curl -s -H "X-aws-ec2-metadata-token: $TOK" "http://169.254.169.254/latest/meta-data/iam/security-credentials/"
No obfuscated payloads: failed
Contains 1 obfuscated or encoded payload pattern.
No base64, hex or compressed blob is decoded and then executed, and no encoded shell commands.
What it found
- skills/hunt-k8s/SKILL.md:183base64 payload piped into a shell or interpreter
echo "$TOKEN" | cut -d. -f2 | tr '_-' '/+' | base64 -d 2>/dev/null | python3 -m json.tool
No pipe-to-shell installers: failed
Runs code fetched at install time in 4 places.
No `curl … | sh` pattern, in the code or in the instructions, that runs code fetched at run time.
What it found (3 of 4)
- skills/hunt-k8s/SKILL.md:85remote script piped into an interpreter
curl -sk "$SRV/api/v1/secrets" | python3 -c 'import sys,json;d=json.load(sys.stdin);print(len(d.get("items",[])),"secrets")' - skills/hunt-k8s/SKILL.md:102remote script piped into an interpreter
curl -sk "$SRV/pods" | python3 -m json.tool 2>/dev/null \ - skills/hunt-k8s/SKILL.md:125remote script piped into an interpreter
curl -s "http://$TARGET:10255/pods" | python3 -m json.tool 2>/dev/null | head
Declares what it does: passed
SKILL.md parses and declares a name and a description.
SKILL.md exists, its frontmatter parses, and it declares a name and a description.
No credential access: passed
Reads no keys, tokens, keychains or credential files.
Neither the code nor the SKILL.md instructions read SSH keys, cloud credentials, keychains, token stores, browser cookie databases or dotfiles that hold secrets.
Pinned to a commit: passed
Scanned elementalsouls/claude-bughunter at e01779570b.
The exact upstream commit SHA that was scanned is recorded, so the result refers to specific bytes.
- Commit
- e01779570b
- Manifest
- skills/hunt-k8s/SKILL.md
- Scanned
- 1 file, 276 lines
About this skill
Hunt K8S — provides AI agent assistance for software development workflows.