Azure Bastion Jit
vinayaklatthe/microsoft-security-skills
Guidance for secure remote VM management in Azure using Azure Bastion combined with Defender for Cloud just-in-time (JIT) VM access.
Creates and queries KubeSphere users, workspaces and projects and assigns built-in roles, defaulting to least privilege and never deleting anything.
$ npx skills add kubesphere/kubesphere --skill kubesphere-multi-tenant-management -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install kubesphere/kubesphere kubesphere-multi-tenant-management --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/kubesphere/kubesphere.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/kubesphere-multi-tenant-management .claude/skills/kubesphere-multi-tenant-management && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "kubesphere-multi-tenant-management" agent skill from https://github.com/kubesphere/kubesphere/tree/master/skills/kubesphere-multi-tenant-management into .claude/skills/kubesphere-multi-tenant-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kubesphere-multi-tenant-management", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/kubesphere/kubesphere/tree/master/skills/kubesphere-multi-tenant-managementType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add kubesphere/kubesphere --skill kubesphere-multi-tenant-management -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install kubesphere/kubesphere kubesphere-multi-tenant-management --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kubesphere/kubesphere.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/kubesphere-multi-tenant-management .agents/skills/kubesphere-multi-tenant-management && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "kubesphere-multi-tenant-management" agent skill from https://github.com/kubesphere/kubesphere/tree/master/skills/kubesphere-multi-tenant-management into .agents/skills/kubesphere-multi-tenant-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kubesphere-multi-tenant-management", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add kubesphere/kubesphere --skill kubesphere-multi-tenant-management -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install kubesphere/kubesphere kubesphere-multi-tenant-management --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kubesphere/kubesphere.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/kubesphere-multi-tenant-management .cursor/skills/kubesphere-multi-tenant-management && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "kubesphere-multi-tenant-management" agent skill from https://github.com/kubesphere/kubesphere/tree/master/skills/kubesphere-multi-tenant-management into .cursor/skills/kubesphere-multi-tenant-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kubesphere-multi-tenant-management", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/kubesphere/kubesphere.git --path skills/kubesphere-multi-tenant-management--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add kubesphere/kubesphere --skill kubesphere-multi-tenant-management -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install kubesphere/kubesphere kubesphere-multi-tenant-management --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kubesphere/kubesphere.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/kubesphere-multi-tenant-management .gemini/skills/kubesphere-multi-tenant-management && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "kubesphere-multi-tenant-management" agent skill from https://github.com/kubesphere/kubesphere/tree/master/skills/kubesphere-multi-tenant-management into .gemini/skills/kubesphere-multi-tenant-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kubesphere-multi-tenant-management", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install kubesphere/kubesphere kubesphere-multi-tenant-managementInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add kubesphere/kubesphere --skill kubesphere-multi-tenant-management -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/kubesphere/kubesphere.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/kubesphere-multi-tenant-management .github/skills/kubesphere-multi-tenant-management && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "kubesphere-multi-tenant-management" agent skill from https://github.com/kubesphere/kubesphere/tree/master/skills/kubesphere-multi-tenant-management into .github/skills/kubesphere-multi-tenant-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kubesphere-multi-tenant-management", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add kubesphere/kubesphere --skill kubesphere-multi-tenant-management -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install kubesphere/kubesphere kubesphere-multi-tenant-management --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kubesphere/kubesphere.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/kubesphere-multi-tenant-management .opencode/skills/kubesphere-multi-tenant-management && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "kubesphere-multi-tenant-management" agent skill from https://github.com/kubesphere/kubesphere/tree/master/skills/kubesphere-multi-tenant-management into .opencode/skills/kubesphere-multi-tenant-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kubesphere-multi-tenant-management", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
kubesphere-multi-tenant-managementCreates and queries KubeSphere users, workspaces and projects and assigns built-in roles, defaulting to least privilege and never deleting anything.
The skill covers user lifecycle, workspace setup, project creation and role binding in KubeSphere, with a bundled ks_api.py script. It is deliberately limited to creating and querying. The agent must not run kubectl edit or delete, must not delete users, workspaces, projects, roles or bindings through the API, and must not create custom roles. Those actions are left to the KubeSphere Console and its approval workflow.
Permissions default to the lowest level: new users get platform-regular, workspace invitations get the regular role for that workspace, and project invitations get viewer, escalating only when you explicitly ask. The skill explains the model: a workspace is the top-level team or business unit and can span several clusters, a project maps to one namespace, and roles come from three tiers of built-in RBAC. A reference document and an evals file ship with it.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 04a29b5. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
pythonkubectlpipFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
docs.kubesphere.com.cnkubernetes.ioFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
KubeSphere Multi-Tenant Management loads about 3.1k tokens when it runs, and up to ~22k if it reads all its reference files. Until then it costs about 82 tokens; SKILL.md has 891 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 891 words (~3,105 tokens).
“The top-level organizational unit in KubeSphere, representing a team, department, or business unit. A workspace can contain multiple projects and serves as the basic boundary for resource grouping and access control. Workspaces can span multiple clusters, enabling centralized management of…”
SKILL.md and 4 other files (scripts, references) in skills/kubesphere-multi-tenant-management of kubesphere/kubesphere.
Open the folder on GitHubat commit 04a29b5
KubeSphere Multi-Tenant Management next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| KubeSphere Multi-Tenant Management this skillkubesphere/kubesphere | 17k | — | ~3.1k | Automated safety check: Pass | Custom licence | |
| Azure Bastion Jitvinayaklatthe/microsoft-security-skills | 175 | — | ~2.2k | Automated safety check: Pass | MIT | |
| Analyzing Kubernetes Audit Logsmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~654 | Automated safety check: Pass | Apache-2.0 | |
| Mimirgrafana/skills | 282 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | |
| Kubernetesnotque/vexjoy-agent | 441 | — | ~1.5k | Automated safety check: Pass | MIT | |
| Defending Kubernetestrilwu/secskills | 157 | — | ~2.2k | Automated safety check: Pass | MIT |
vinayaklatthe/microsoft-security-skills
Guidance for secure remote VM management in Azure using Azure Bastion combined with Defender for Cloud just-in-time (JIT) VM access.
mukul975/Anthropic-Cybersecurity-Skills
Parses Kubernetes API server audit logs (JSON lines) to detect exec-into-pod, secret access, RBAC modifications, privileged pod creation, and anonymous API access, and builds SIEM detection rules…
grafana/skills
Stand up Grafana Mimir for horizontally scalable, multi-tenant, long-term Prometheus + OTLP metrics storage.
notque/vexjoy-agent
Kubernetes operations: debugging, security, RBAC, and infrastructure tooling.
trilwu/secskills
Harden and monitor a Kubernetes cluster against the attacks that actually happen — RBAC least privilege and escalation paths, Pod Security Admission enforcement, network policy default-deny, secrets…
jeremylongshore/tons-of-skills-marketplace
Review CAST AI identity, Kubernetes RBAC, cloud IAM, Kvisor, network, and evidence boundaries against enabled features.
kubesphere/kubesphere
Installs, checks and troubleshoots the KubeSphere ServiceMesh extension (Istio, Kiali, Jaeger), including grayscale release, sidecar injection, topology and tracing issues.
kubesphere/kubesphere
Deploys KubeEye on KubeSphere and writes InspectRule and InspectPlan resources to inspect cluster health, then retrieves the inspection reports.
kubesphere/kubesphere
Queries, creates, updates, binds and troubleshoots NodeGroup resources in the edgewize nodegroup project through a bundled authenticated API script.
kubesphere/kubesphere
Installs and configures the WizTelemetry Platform Service extension for KubeSphere, the shared API server behind its observability extensions.
kubesphere/kubesphere
Runs the lifecycle of FrontendExtension resources in a Kubernetes cluster: create, rebuild, package, publish, unpublish, delete and debug stuck states.
kubesphere/kubesphere
Operates FrontendIntegration resources and the frontend-forge extension with kubectl: create from YAML, update, enable, disable, delete, inspect and troubleshoot builds.
Works with
Categories
Creates and queries KubeSphere users, workspaces and projects and assigns built-in roles, defaulting to least privilege and never deleting anything. py script. It is deliberately limited to creating and querying.
KubeSphere Multi-Tenant Management fits situations like: creating a KubeSphere user with a safe default role; setting up a workspace and the projects inside it for a team; inviting people to a workspace or project with the right built-in role; looking up who has access to which workspace or project.
Run `npx skills add kubesphere/kubesphere --skill kubesphere-multi-tenant-management -a claude-code`. Or copy the skill folder (skills/kubesphere-multi-tenant-management in kubesphere/kubesphere) into .claude/skills/kubesphere-multi-tenant-management in your project. Claude Code loads it when a task matches its description.
Run `npx skills add kubesphere/kubesphere --skill kubesphere-multi-tenant-management -a codex`. Or copy the skill folder (skills/kubesphere-multi-tenant-management in kubesphere/kubesphere) into .agents/skills/kubesphere-multi-tenant-management in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kubesphere/kubesphere --skill kubesphere-multi-tenant-management -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/kubesphere-multi-tenant-management, .gemini/skills/kubesphere-multi-tenant-management, .github/skills/kubesphere-multi-tenant-management and .opencode/skills/kubesphere-multi-tenant-management in your project.
Going by SKILL.md and its folder, KubeSphere Multi-Tenant Management needs Python for the scripts in its folder and the command-line tools its instructions call (python, kubectl and pip). Our summary lists: A KubeSphere installation the agent can reach; Python, to run scripts/ks_api.py.
SKILL.md names 2 domains. As links in the text: docs.kubesphere.com.cn and kubernetes.io. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
KubeSphere Multi-Tenant Management has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.
About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 19k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with KubeSphere Multi-Tenant Management: Azure Bastion Jit (vinayaklatthe/microsoft-security-skills, 175 stars), Analyzing Kubernetes Audit Logs (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Mimir (grafana/skills, 282 stars) and Kubernetes (notque/vexjoy-agent, 441 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
kubesphere (a GitHub organization) maintains it in kubesphere/kubesphere, which has 17,056 GitHub stars. The repository holds 32 skills in this directory. The repository was last updated on July 15, 2026.
Source: kubesphere/kubesphere on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.