Kubeshark Installer
kubeshark/kubeshark
Installs and configures Kubeshark on a Kubernetes cluster, choosing between the quick CLI path and a Helm install with custom values.
Guided install / scale-out of a sandbox Kubernetes cluster for the Lego-RL k8s backend (kubeadm 1.32 + containerd + flannel + ImageVolume, optionally nydus / a shared registry / an isolated dockerd).
The automated check flagged lines worth reading first. See the safety section below.
$ npx skills add LegoX/Lego-RL --skill k8s-sandbox-install -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install LegoX/Lego-RL k8s-sandbox-install --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/LegoX/Lego-RL.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/plugins/rl-plugin/skills/k8s-sandbox-install .claude/skills/k8s-sandbox-install && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "k8s-sandbox-install" agent skill from https://github.com/LegoX/Lego-RL/tree/main/.claude/plugins/rl-plugin/skills/k8s-sandbox-install into .claude/skills/k8s-sandbox-install/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "k8s-sandbox-install", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/LegoX/Lego-RL/tree/main/.claude/plugins/rl-plugin/skills/k8s-sandbox-installType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add LegoX/Lego-RL --skill k8s-sandbox-install -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install LegoX/Lego-RL k8s-sandbox-install --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LegoX/Lego-RL.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/plugins/rl-plugin/skills/k8s-sandbox-install .agents/skills/k8s-sandbox-install && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "k8s-sandbox-install" agent skill from https://github.com/LegoX/Lego-RL/tree/main/.claude/plugins/rl-plugin/skills/k8s-sandbox-install into .agents/skills/k8s-sandbox-install/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "k8s-sandbox-install", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add LegoX/Lego-RL --skill k8s-sandbox-install -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install LegoX/Lego-RL k8s-sandbox-install --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LegoX/Lego-RL.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/plugins/rl-plugin/skills/k8s-sandbox-install .cursor/skills/k8s-sandbox-install && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "k8s-sandbox-install" agent skill from https://github.com/LegoX/Lego-RL/tree/main/.claude/plugins/rl-plugin/skills/k8s-sandbox-install into .cursor/skills/k8s-sandbox-install/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "k8s-sandbox-install", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/LegoX/Lego-RL.git --path .claude/plugins/rl-plugin/skills/k8s-sandbox-install--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add LegoX/Lego-RL --skill k8s-sandbox-install -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install LegoX/Lego-RL k8s-sandbox-install --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LegoX/Lego-RL.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/plugins/rl-plugin/skills/k8s-sandbox-install .gemini/skills/k8s-sandbox-install && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "k8s-sandbox-install" agent skill from https://github.com/LegoX/Lego-RL/tree/main/.claude/plugins/rl-plugin/skills/k8s-sandbox-install into .gemini/skills/k8s-sandbox-install/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "k8s-sandbox-install", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install LegoX/Lego-RL k8s-sandbox-installInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add LegoX/Lego-RL --skill k8s-sandbox-install -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/LegoX/Lego-RL.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/plugins/rl-plugin/skills/k8s-sandbox-install .github/skills/k8s-sandbox-install && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "k8s-sandbox-install" agent skill from https://github.com/LegoX/Lego-RL/tree/main/.claude/plugins/rl-plugin/skills/k8s-sandbox-install into .github/skills/k8s-sandbox-install/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "k8s-sandbox-install", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add LegoX/Lego-RL --skill k8s-sandbox-install -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install LegoX/Lego-RL k8s-sandbox-install --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LegoX/Lego-RL.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/plugins/rl-plugin/skills/k8s-sandbox-install .opencode/skills/k8s-sandbox-install && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "k8s-sandbox-install" agent skill from https://github.com/LegoX/Lego-RL/tree/main/.claude/plugins/rl-plugin/skills/k8s-sandbox-install into .opencode/skills/k8s-sandbox-install/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "k8s-sandbox-install", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
k8s-sandbox-installGuided install / scale-out of a sandbox Kubernetes cluster for the Lego-RL k8s backend (kubeadm 1.32 + containerd + flannel + ImageVolume, optionally nydus / a shared registry / an isolated dockerd).
K8s Sandbox Install is an agent skill from LegoX/Lego-RL. Guided install / scale-out of a sandbox Kubernetes cluster for the Lego-RL k8s backend (kubeadm 1.32 + containerd + flannel + ImageVolume, optionally nydus / a shared registry / an isolated dockerd). Probes the target machines for differences (OS, network, disk, pre-existing cluster) and never asks for what it can detect itself; finishes by generating a site.<name.env wired for the training side. Triggers: install kubernetes, set up a cluster, add a worker node, join worker, new cluster, sandbox cluster deployment.
Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering Container orchestration. It works with Kubernetes. The repository describes itself as: Lego-RL: Harness-Native Reinforcement Learning for Coding Agents. The licence is Apache-2.0.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 0731c95. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
kubectlcurlaptFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use kubectl and curl, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
K8s Sandbox Install loads about 2.9k tokens when it runs. Until then it costs about 135 tokens; SKILL.md has 1,453 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found patterns that need a careful read before installing.
If the current shell's `known_hosts`, `~/.ssh/config` or command history# save the join command; set up ~/.kube/config; apply flannelAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from LegoX/Lego-RL at commit 0731c95, republished under its Apache-2.0 licence (© LegoX). 1,453 words, ~2,905 tokens.
.claude/skills/k8s-sandbox-install/SKILL.md (or your agent's skills folder).You are an install wizard. The goal: stand up a cluster on the user's machines that can run the Lego-RL Kubernetes backend, with versions, features and guardrails aligned to the baseline below.
Core principle: never ask for anything you can probe. The user should usually have to supply exactly one thing — how to reach the nodes over SSH. Everything else (OS, disks, subnets, egress, an existing cluster, shared storage) you determine yourself. Only when a decision is ambiguous or risky do you go back to the user, and then with probe results plus a recommendation, not an open question. Never copy commands blindly: probe first, then decide, at every stage.
Background reading before you start:
scripts/lib/site.example.env — every cluster-specific value the training side consumes,
and how the site.env layer works.docs/content/docs/run-training/backends.mdx — what the k8s backend expects.docs/content/docs/data-preparation.mdx — the environment-image story (prebuilt registry
vs. in-pod inline build), which decides whether this cluster needs a registry at all.kubeadm/kubelet/kubectl 1.32.13 (ImageVolume needs ≥1.32; 1.31 has a readonly bug and is
unusable), containerd 2.2.x, flannel, pause:3.10, CNI plugins ≥v1.5. apt-mark hold all of them.
Ask the user only: how to log into the nodes (IP list + SSH user/password or key, whether
root is available). If the current shell's known_hosts, ~/.ssh/config or command history
already hint at it, try that first — if it works, you do not even need to ask.
With SSH in hand, probe everything (collect per node, present one table before continuing):
| Item | How to probe | Automatic decision rule |
|---|---|---|
| OS / kernel / arch | /etc/os-release, uname -rm | Ubuntu 22.04/24.04 + amd64 → proceed; CentOS/arm64 → list the differences and confirm with the user |
| Which node is control-plane | compare cores / memory / disk | default to the balanced node, not the one with the largest disk (keep that for builds/storage). State the choice and the reason; change it only if the user objects |
| Large-disk path | lsblk / df -h for the biggest writable mount | one obvious large disk → use <mount>/storage; if the root disk is the largest, warn that images will consume hundreds of GB to TB and ask whether that is acceptable or another disk should be attached |
| Subnet conflicts | ip route vs 10.244.0.0/16, 10.96.0.0/12 | on conflict, switch podSubnet automatically (e.g. 10.245.0.0/16) and update flannel's Network to match — inform, do not ask |
| Egress | curl -sI --max-time 5 against pkgs.k8s.io / download.docker.com / registry-1.docker.io / ghcr.io | all reachable → proceed; otherwise probe `env |
| Existing cluster / leftovers | kubectl get nodes, systemctl status kubelet, ss -ltn | grep 6443, ls /etc/kubernetes /var/lib/etcd | live cluster → switch to the add-node flow; leftovers → list them, and kubeadm reset always requires user confirmation |
| Shared storage | mount | grep -E 'nfs|alinas|cpfs|gpfs|lustre' | present → nydus / hostPath mounts can be enabled; absent → skip nydus, leave hostPath empty |
| swap / time / hostname | swapon --show, timedatectl, hostname | fix all of these directly (disable swap + fstab, install chrony, lowercase uppercase hostnames) and report afterwards |
| Usable registry | probe known addresses (already configured under certs.d, or seen in the user's shell history) with curl /v2/ | list what answers as a recommendation; if none, default to the pure inline-build path (no registry needed) without asking |
Optional-component defaults (do not ask; explain in the final report, the user can request more): isolated dockerd = only if the machine already has docker or the user mentioned building images; nydus = only with a shared FS and obtainable binaries; metrics-server = install (harmless); Docker Hub pull secret = only ask for a PAT if private images turn out to be needed.
Work through the Stage 0 table item by item and produce a node × check status table.
Resource limits: CPU < 16 warns (work around with kubeadm --ignore-preflight-errors=NumCPU);
ports 6443 / 10250 / 2379-2380 / 8472(udp) must be free; nodes must reach each other with
ping + nc. Fix what you find — do not enter Stage 2 with known problems.
Make every step idempotent so a re-run is safe:
/etc/hosts (use a marked block, e.g. # >>> k8s-sandbox-cluster >>>,
and delete the old block on re-run). Write the full list on every node so resolution
works in both directions. Add any registry alias you detected a need for at the same time.bridge-nf-call-iptables, ip_forward)max_user_watches=1048576, max_user_instances=8192, required for
high pod density).<disk>/containerd (plus optional <disk>/nydus-cache,
<disk>/docker).containerd.io=2.2.x or Ubuntu's containerd=2.2.1 — pick one, but keep it identical
cluster-wide), kubelet/kubeadm/kubectl=1.32.13, kubernetes-cni.containerd config default, then edit — note 2.x emits
single-quoted TOML, so sed must match single quotes):root = '<disk>/containerd'SystemdCgroup = trues|pause:3.10.1|pause:3.10|g/etc/containerd/certs.d/<host:port>/hosts.toml for each detected registry
(add skip_verify = true for a plain-HTTP registry)./opt/cni/bin (flannel does not bundle them; without them nodes
sit at NetworkPluginNotReady).systemctl restart containerd && systemctl enable containerd kubelet.sync_remove GC, and register the unpack platform
with the containerd transfer service.Generate /root/kubeadm-config.yaml, filling IPs / hostnames / podSubnet from the Stage 0
probe results. Key points:
apiServer.extraArgs: feature-gates=ImageVolume=true and
KubeletConfiguration.featureGates.ImageVolume: true — both sides are required.maxPods derived from the detected core count: 16c → 32; 64c+ → 128–200. Err on the low side.controlPlaneEndpoint even for a single master, so a later HA expansion does not need
certificates re-signed.imageGCHighThresholdPercent: 90 / Low: 80, containerLogMaxSize: 100Mi, and
evictionPressureTransitionPeriod: 5m (0s amplifies DiskPressure evictions).kubeadm config images pull --config=/root/kubeadm-config.yaml # pull first: surfaces network problems early
kubeadm init --config=/root/kubeadm-config.yaml --upload-certs --ignore-preflight-errors=NumCPU
# save the join command; set up ~/.kube/config; apply flannel
# (if podSubnet changed, edit the flannel yml's Network first)kubeadm join (if the token expired, regenerate with kubeadm token create --print-join-command).
After each join, verify ImageVolume: true propagated into /var/lib/kubelet/config.yaml;
if not, add it by hand and restart kubelet. Once every node is Ready, a small cluster can drop
the master's NoSchedule taint.
kubectl get nodes -o wide all Ready, coredns Running, cross-node pod ping works
(flannel VXLAN 8472/udp open).volumes[].image. A
readonly must be true error means the kubelet version is wrong.crictl pull <registry>/<known-image> from any node. When probing
whether an image exists, curl must send a full Accept header including the OCI index
type, or you get a false 404.kubectl describe nodes | grep -A1 pods:.ctr plugins ls | grep nydus plus pulling one nydus
image), isolated dockerd (Root Dir on the large disk; the k8s containerd namespace is only
k8s.io), pull secret (start a pod from a private image).Copy the master's admin.conf to the training machine (if server: is 127.0.0.1, replace
it with the real IP). Check first whether a kubeconfig pointing at the same server already
exists and reuse it rather than creating a duplicate.
Generate scripts/lib/site.<name>.env from scripts/lib/site.example.env, filling every
value from the probe results and noting where each came from:
K8S_KUBECONFIG ← the path from the previous step;HARBOR_OPENSWE_IMAGE_REGISTRY ← a registry detected in Stage 0 and confirmed with a
real crictl pull; none → leave empty (inline build is the fallback);HARBOR_NYDUS_MIRROR ← only if nydus / a mirror was installed;HARBOR_HOSTPATH_MOUNTS ← only paths you verified exist with ls on every node, else null;HARBOR_CLUSTER_DNS_IP ← kubectl -n kube-system get svc kube-dns -o jsonpath='{.spec.clusterIP}',
needed explicitly only when it is not 10.96.0.10;MODEL_ROOT / NEW_VERL_DIR ← carry over from the existing site.env (these belong to the
training machine and do not change with the cluster).Select it at run time with SITE_ENV_FILE=scripts/lib/site.<name>.env. Do not overwrite the
default site.env — another run may still be using the old cluster.
If egress isolation is on, confirm on every node that HARBOR_NETADMIN_IMAGE is pullable
(if it is not, every pod hangs). If it is not, mirror it into the user's registry first.
Health-check with SITE_ENV_FILE=... PREFLIGHT_ONLY=1 against the runner (or /rl:check).
Do a 1-node smoke run before a real one.
kubeadm reset, any edit to an existing /etc/kubernetes, or touching a cluster someone
else is running → confirm with the user first.apt upgrade. Remind the user afterwards that the relevant packages are held..bak file in /etc/kubernetes/manifests/ — the kubelet loads it as a static pod.© LegoX, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/plugins/rl-plugin/skills/k8s-sandbox-install of LegoX/Lego-RL.
Open the folder on GitHubat commit 0731c95
K8s Sandbox Install next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| K8s Sandbox Install this skillLegoX/Lego-RL | 113 | — | ~2.9k | Automated safety check: Warn | Apache-2.0 | |
| Kubeshark Installerkubeshark/kubeshark | 12k | — | ~3.6k | Automated safety check: Notes | Apache-2.0 | |
| KubeSphere Multi-Tenant Managementkubesphere/kubesphere | 17k | — | ~3.1k | Automated safety check: Pass | Custom licence | |
| Sim Helmsimstudioai/sim | 30k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | |
| Helm Chart ScaffoldingCybereason-Public/owLSM | 280 | 13 repos | ~381 | Automated safety check: Pass | GPL-2.0 | |
| Kubeshark KFL2 Filter Referencekubeshark/kubeshark | 12k | — | ~3.6k | Automated safety check: Pass | Apache-2.0 |
kubeshark/kubeshark
Installs and configures Kubeshark on a Kubernetes cluster, choosing between the quick CLI path and a Helm install with custom values.
kubesphere/kubesphere
Creates and queries KubeSphere users, workspaces and projects and assigns built-in roles, defaulting to least privilege and never deleting anything.
simstudioai/sim
Install, upgrade, and operate the Sim Helm chart on Kubernetes.
Cybereason-Public/owLSM
Comprehensive guidance for creating, organizing, and managing Helm charts for packaging and deploying Kubernetes applications.
kubeshark/kubeshark
Syntax reference for KFL2, the CEL-based display filter language used to search Kubernetes network traffic captured by Kubeshark, loaded before any filter is written.
kubesphere/kubesphere
Installs, checks and troubleshoots the KubeSphere ServiceMesh extension (Istio, Kiali, Jaeger), including grayscale release, sidecar injection, topology and tracing issues.
LegoX/Lego-RL
Compose, edit, refactor, and validate Lego-RL train/eval/infer .env configs and reusable scripts/templates modules.
LegoX/Lego-RL
Preflight a Lego-RL config: answer "is it safe to launch this run right now?".
LegoX/Lego-RL
Bring up the Lego-RL training dashboard (webui/) on whatever machine you are on, adapting to that box's layout instead of assuming this repo's paths.
LegoX/Lego-RL
Preflight and launch a Lego-RL run (train, eval or infer). An agent skill from LegoX/Lego-RL.
LegoX/Lego-RL
Diagnose a Lego-RL run that is already in flight (or just finished): which run is alive, how far it has got, and whether its numbers are healthy.
LegoX/Lego-RL
One-to-one Codex counterpart for Claude /rl:check. An agent skill from LegoX/Lego-RL.
Works with
Categories
Guided install / scale-out of a sandbox Kubernetes cluster for the Lego-RL k8s backend (kubeadm 1.32 + containerd + flannel + ImageVolume, optionally nydus / a shared registry / an isolated dockerd). K8s Sandbox Install is an agent skill from LegoX/Lego-RL.32 + containerd + flannel + ImageVolume, optionally nydus / a shared registry / an isolated dockerd).
K8s Sandbox Install fits situations like: tasks that involve Container orchestration.
Run `npx skills add LegoX/Lego-RL --skill k8s-sandbox-install -a claude-code`. Or copy the skill folder (.claude/plugins/rl-plugin/skills/k8s-sandbox-install in LegoX/Lego-RL) into .claude/skills/k8s-sandbox-install in your project. Claude Code loads it when a task matches its description.
Run `npx skills add LegoX/Lego-RL --skill k8s-sandbox-install -a codex`. Or copy the skill folder (.claude/plugins/rl-plugin/skills/k8s-sandbox-install in LegoX/Lego-RL) into .agents/skills/k8s-sandbox-install in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LegoX/Lego-RL --skill k8s-sandbox-install -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/k8s-sandbox-install, .gemini/skills/k8s-sandbox-install, .github/skills/k8s-sandbox-install and .opencode/skills/k8s-sandbox-install in your project.
Going by SKILL.md and its folder, K8s Sandbox Install needs the command-line tools its instructions call (kubectl, curl and apt). Our summary lists: Docker.
SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md flagged 2 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.
K8s Sandbox Install is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with K8s Sandbox Install: Kubeshark Installer (kubeshark/kubeshark, 12k stars), KubeSphere Multi-Tenant Management (kubesphere/kubesphere, 17k stars), Sim Helm (simstudioai/sim, 30k stars) and Helm Chart Scaffolding (Cybereason-Public/owLSM, 280 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
LegoX (a GitHub organization) maintains it in LegoX/Lego-RL, which has 113 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on October 8, 2026.
Source: LegoX/Lego-RL on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.