Agent skill

KubeSphere WizTelemetry Auditing

by kubesphere in kubesphere/kubesphere

Installs and configures the WizTelemetry Auditing extension for KubeSphere, which collects and stores Kubernetes audit events, and covers the audit query API.

Custom licenceAuto-check passedDevOps & Cloud

Install KubeSphere WizTelemetry Auditing

skills CLI
$ npx skills add kubesphere/kubesphere --skill whizard-auditing -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install kubesphere/kubesphere whizard-auditing --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/kubesphere/kubesphere.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/whizard-auditing .claude/skills/whizard-auditing && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
whizard-auditing
GitHub stars
17k
Token cost
~2.2k tokens
SKILL.md length
601 words
Files
1
Skills in repo
32
Repo updated
First seen
Licence
Custom licence

At a glance

Installs and configures the WizTelemetry Auditing extension for KubeSphere, which collects and stores Kubernetes audit events, and covers the audit query API.

  • Works in 2 steps: Get Available Clusters and Confirm Target → Get Latest Version (if not provided by…
  • Installing Kubernetes audit event collection in KubeSphere
  • SKILL.md covers Overview, When to Use, Components and Dependencies, plus 4 more sections
  • Calls kubectl and curl; reaches whizard-telemetry-apiserver.extension-whizard-telemetry.svc

What it does

This skill covers WizTelemetry Auditing, the KubeSphere observability component that collects, processes and stores audit events from Kubernetes and KubeSphere. The extension ships a single component, `kube-auditing`, enabled by default, and requires two others to be present: the WizTelemetry Platform Service and the WizTelemetry Data Pipeline. It also explains how audit events are collected and how to read them back through the audit query API.

Prerequisites come first: list the clusters and have you confirm the targets unless you named them, then look up the latest extension version. The InstallPlan has to be named `whizard-auditing`. Its YAML config must follow the provided template exactly, with no extra fields and no change to the structure, and every placeholder must be replaced with a real value before the plan is applied.

When your agent uses it

  • Installing Kubernetes audit event collection in KubeSphere
  • Understanding how audit events flow from collection to storage
  • Querying audit events through the audit query API

Example prompts

  • “Install the KubeSphere auditing extension on the host cluster.”
  • “Which extensions must be installed before WizTelemetry Auditing will work?”
  • “Show me how to query audit events with the audit API.”

Requirements

  • The WizTelemetry Platform Service and Data Pipeline extensions
  • kubectl access to a KubeSphere cluster

Workflow steps

2 steps, taken from the step headings in SKILL.md.

  1. Get Available Clusters and Confirm Target
  2. Get Latest Version (if not provided by user)

What it can do on your machine

Read from SKILL.md and the folder at commit 04a29b5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • kubectl
    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • whizard-telemetry-apiserver.extension-whizard-telemetry.svc

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

KubeSphere WizTelemetry Auditing loads about 2.2k tokens when it runs. Until then it costs about 36 tokens; SKILL.md has 601 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~36
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 601 words (~2,195 tokens).

“WizTelemetry Auditing is an extension component in the KubeSphere Observability Platform for Kubernetes and KubeSphere audit event collection, processing, and storage.”

— opening of SKILL.md by kubesphere, Custom licence
name
whizard-auditing

Read the full SKILL.md on GitHub

Files

Just SKILL.md in skills/whizard-auditing of kubesphere/kubesphere.

Open the folder on GitHubat commit 04a29b5

Compare with similar skills

KubeSphere WizTelemetry Auditing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

KubeSphere WizTelemetry Auditing compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
KubeSphere WizTelemetry Auditing this skillkubesphere/kubesphere17k—~2.2kAutomated safety check: PassCustom licence
Implementing Ebpf Security Monitoringmukul975/Anthropic-Cybersecurity-Skills34k—~2.4kAutomated safety check: NotesApache-2.0
Kubeshark Installerkubeshark/kubeshark12k—~3.6kAutomated safety check: NotesApache-2.0
Kubeshark KFL2 Filter Referencekubeshark/kubeshark12k—~3.6kAutomated safety check: PassApache-2.0
Kubernetes Network Root Cause Analysiskubeshark/kubeshark12k—~5.3kAutomated safety check: PassApache-2.0
Kubernetes Troubleshooting with Inspektor Gadgetinspektor-gadget/inspektor-gadget2.9k—~2.3kAutomated safety check: PassApache-2.0

Similar skills

  • Implementing Ebpf Security Monitoring

    mukul975/Anthropic-Cybersecurity-Skills

    Implements eBPF-based security monitoring using Cilium Tetragon for real-time process execution tracking, network connection observability, file access auditing, and runtime enforcement.

    34k GitHub stars~2.4k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: notes
  • Kubeshark Installer

    kubeshark/kubeshark

    Installs and configures Kubeshark on a Kubernetes cluster, choosing between the quick CLI path and a Helm install with custom values.

    12k GitHub stars~3.6k tokensUpdated 6 days ago
    DevOps & CloudAuto-check: notes
  • Syntax reference for KFL2, the CEL-based display filter language used to search Kubernetes network traffic captured by Kubeshark, loaded before any filter is written.

    12k GitHub stars~3.6k tokensUpdated 6 days ago
    DevOps & CloudAuto-check passed
  • Investigates past Kubernetes incidents from Kubeshark traffic snapshots: takes captures, dissects API calls, extracts PCAPs and compares traffic over time.

    12k GitHub stars~5.3k tokensUpdated 6 days ago
    DevOps & CloudAuto-check passed
  • Kubernetes Troubleshooting with Inspektor Gadget

    inspektor-gadget/inspektor-gadget

    Traces what the kernel is doing for a misbehaving pod using Inspektor Gadget's eBPF tools, tagged with namespace, pod, container and node, without changing workloads.

    2.9k GitHub stars~2.3k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Logfire Infrastructure

    pydantic/skills

    Official

    Monitor hosts, Docker containers, Kubernetes clusters, database/queue/cache servers, and cloud-provider metrics with Pydantic Logfire — no application code required.

    140 GitHub stars~1.8k tokensUpdated 6 days ago
    DevOps & CloudAuto-check passed

More from kubesphere/kubesphere

All 32 skills in this repo
  • Creates and queries KubeSphere users, workspaces and projects and assigns built-in roles, defaulting to least privilege and never deleting anything.

    17k GitHub stars~3.1k tokensUpdated 2 mo ago
    Auto-check passed
  • KubeSphere ServiceMesh Manager

    kubesphere/kubesphere

    Installs, checks and troubleshoots the KubeSphere ServiceMesh extension (Istio, Kiali, Jaeger), including grayscale release, sidecar injection, topology and tracing issues.

    17k GitHub stars~2.4k tokensUpdated 2 mo ago
    Auto-check passed
  • KubeEye Cluster Inspection

    kubesphere/kubesphere

    Deploys KubeEye on KubeSphere and writes InspectRule and InspectPlan resources to inspect cluster health, then retrieves the inspection reports.

    17k GitHub stars~3.6k tokensUpdated 2 mo ago
    Auto-check passed
  • KubeSphere NodeGroup Operations

    kubesphere/kubesphere

    Queries, creates, updates, binds and troubleshoots NodeGroup resources in the edgewize nodegroup project through a bundled authenticated API script.

    17k GitHub stars~1.9k tokensUpdated 2 mo ago
    Auto-check passed
  • WizTelemetry Platform Service

    kubesphere/kubesphere

    Installs and configures the WizTelemetry Platform Service extension for KubeSphere, the shared API server behind its observability extensions.

    17k GitHub stars~1.8k tokensUpdated 2 mo ago
    Auto-check passed
  • Runs the lifecycle of FrontendExtension resources in a Kubernetes cluster: create, rebuild, package, publish, unpublish, delete and debug stuck states.

    17k GitHub stars~3.2k tokensUpdated 2 mo ago
    Auto-check passed

Works with

Questions about KubeSphere WizTelemetry Auditing

What does KubeSphere WizTelemetry Auditing do?

Installs and configures the WizTelemetry Auditing extension for KubeSphere, which collects and stores Kubernetes audit events, and covers the audit query API. This skill covers WizTelemetry Auditing, the KubeSphere observability component that collects, processes and stores audit events from Kubernetes and KubeSphere. The extension ships a single component, `kube-auditing`, enabled by default, and requires two others to be present: the WizTelemetry Platform Service and the WizTelemetry Data Pipeline.

When should I use KubeSphere WizTelemetry Auditing?

KubeSphere WizTelemetry Auditing fits situations like: installing Kubernetes audit event collection in KubeSphere; understanding how audit events flow from collection to storage; querying audit events through the audit query API.

How do I install KubeSphere WizTelemetry Auditing in Claude Code?

Run `npx skills add kubesphere/kubesphere --skill whizard-auditing -a claude-code`. Or copy the skill folder (skills/whizard-auditing in kubesphere/kubesphere) into .claude/skills/whizard-auditing in your project. Claude Code loads it when a task matches its description.

How do I install KubeSphere WizTelemetry Auditing in Codex?

Run `npx skills add kubesphere/kubesphere --skill whizard-auditing -a codex`. Or copy the skill folder (skills/whizard-auditing in kubesphere/kubesphere) into .agents/skills/whizard-auditing in your project. Codex loads it when a task matches its description.

Can I use KubeSphere WizTelemetry Auditing in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kubesphere/kubesphere --skill whizard-auditing -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/whizard-auditing, .gemini/skills/whizard-auditing, .github/skills/whizard-auditing and .opencode/skills/whizard-auditing in your project.

What does KubeSphere WizTelemetry Auditing need to run?

Going by SKILL.md and its folder, KubeSphere WizTelemetry Auditing needs the command-line tools its instructions call (kubectl and curl). Our summary lists: The WizTelemetry Platform Service and Data Pipeline extensions; kubectl access to a KubeSphere cluster.

Does KubeSphere WizTelemetry Auditing access the network?

SKILL.md names 1 domain. In commands or code: whizard-telemetry-apiserver.extension-whizard-telemetry.svc; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is KubeSphere WizTelemetry Auditing safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does KubeSphere WizTelemetry Auditing use?

KubeSphere WizTelemetry Auditing has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does KubeSphere WizTelemetry Auditing use?

About 2.2k tokens (SKILL.md is roughly 8.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to KubeSphere WizTelemetry Auditing?

Skills that share tags, products or a category with KubeSphere WizTelemetry Auditing: Implementing Ebpf Security Monitoring (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Kubeshark Installer (kubeshark/kubeshark, 12k stars), Kubeshark KFL2 Filter Reference (kubeshark/kubeshark, 12k stars) and Kubernetes Network Root Cause Analysis (kubeshark/kubeshark, 12k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains KubeSphere WizTelemetry Auditing?

kubesphere (a GitHub organization) maintains it in kubesphere/kubesphere, which has 17,059 GitHub stars. The repository holds 32 skills in this directory. The repository was last updated on July 15, 2026.

Source: kubesphere/kubesphere on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.