Agent skill

KubeShark for Kubernetes

by LukasNiessen in LukasNiessen/kubernetes-skill

Keeps Kubernetes manifests, Helm charts and policies grounded by diagnosing six failure modes, such as insecure defaults and API drift, and loading only matching references.

MITAuto-check passedDevOps & Cloud

Install KubeShark for Kubernetes

skills CLI
$ npx skills add LukasNiessen/kubernetes-skill --skill kubernetes-skill -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install LukasNiessen/kubernetes-skill kubernetes-skill --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
kubernetes-skill
GitHub stars
446
Token cost
~1.2k tokens
SKILL.md length
430 words
Files
87 (incl. references, assets)
Skills in repo
1
Repo updated
First seen
Licence
MIT

At a glance

Keeps Kubernetes manifests, Helm charts and policies grounded by diagnosing six failure modes, such as insecure defaults and API drift, and loading only matching references.

  • Works in 7 steps: Capture execution context → Diagnose likely failure mode(s) → Load only the relevant reference file(s) → …
  • Generating Kubernetes manifests with secure, resource-aware defaults
  • SKILL.md covers 1) Capture execution context, 2) Diagnose likely failure…, 3) Load only the relevant… and 4) Propose fix path with…, plus 3 more sections
  • Calls kubectl

What it does

The agent works top to bottom. It first records context: cluster version and distribution, namespace and environment criticality, workload type, deployment method, policy enforcement, cloud provider and CNI, and add-ons such as GitOps, observability, ingress or service mesh, stating assumptions when something is unknown. It then picks one or more failure modes: insecure workload defaults, resource starvation, network exposure, privilege sprawl, fragile rollouts and API drift.

Each failure mode has its own reference file, and the agent loads only those that apply, plus supplemental references for deployment, stateful and job patterns, security hardening, observability, multi-tenancy, storage, Helm, Kustomize and validation. Conditional references load only when a signal appears, for example EKS patterns when AWS, IRSA or Karpenter come up. The aim is to stop models inventing Kubernetes details by tying output to official best practices.

When your agent uses it

  • Generating Kubernetes manifests with secure, resource-aware defaults
  • Reviewing manifests or Helm charts for risky settings
  • Migrating manifests off deprecated APIs
  • Working on EKS, GKE, AKS or OpenShift specific configuration

Example prompts

  • “Write a Deployment and Service for our API with security contexts, requests, limits and a PDB.”
  • “Review this Helm chart for privilege sprawl and missing network policies.”
  • “Update these manifests to stop using deprecated apiVersions.”

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Capture execution context
  2. Diagnose likely failure mode(s)
  3. Load only the relevant reference file(s)
  4. Propose fix path with explicit risk controls
  5. Generate implementation artifacts
  6. Validate before finalize
  7. Output contract

What it can do on your machine

Read from SKILL.md and the folder at commit 34f93c1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • kubectl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use kubectl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

KubeShark for Kubernetes loads about 1.2k tokens when it runs, and up to ~52k if it reads all its reference files. Until then it costs about 110 tokens; SKILL.md has 430 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~110
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~52k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from LukasNiessen/kubernetes-skill at commit 34f93c1, republished under its MIT licence (© LukasNiessen). 430 words, ~1,187 tokens.

Download SKILL.mdSave it as .claude/skills/kubernetes-skill/SKILL.md (or your agent's skills folder). This skill also uses 86 other files; get the full folder from GitHub.
name
kubernetes-skill
description
Prevent Kubernetes hallucinations by diagnosing and fixing failure modes: insecure workload defaults, resource starvation, network exposure, privilege sprawl, fragile rollouts, and API drift. Use when generating, reviewing, refactoring, or migrating manifests, Helm charts, Kustomize overlays, cluster policies, and platform-specific Kubernetes work for EKS, GKE, AKS, OpenShift, GitOps controllers, or observability stacks.

KubeShark: Failure-Mode Workflow for Kubernetes

Run this workflow top to bottom.

1) Capture execution context

Record before writing manifests:

  • cluster version (e.g. 1.30, 1.31) and distribution (EKS, GKE, AKS, k3s, vanilla)
  • target namespace and environment criticality (dev/staging/prod)
  • workload type (Deployment, StatefulSet, Job, CronJob, DaemonSet)
  • deployment method (raw YAML, Helm, Kustomize, operator-managed)
  • policy enforcement (Pod Security Admission level, Kyverno, OPA/Gatekeeper)
  • cloud provider and CNI (affects networking, storage classes, load balancers)
  • platform controllers/add-ons (GitOps, observability, ingress, service mesh, autoscaling)

If unknown, state assumptions explicitly.

2) Diagnose likely failure mode(s)

Select one or more based on user intent and risk:

  • insecure workload defaults: missing security contexts, PSS violations, host access
  • resource starvation: missing requests/limits, no PDB, scheduling chaos
  • network exposure: flat networking, missing policies, wrong Service types, DNS issues
  • privilege sprawl: overly permissive RBAC, leaked secrets, excess ServiceAccount rights
  • fragile rollouts: misconfigured probes, mutable tags, unsafe update strategies
  • API drift: wrong apiVersion, deprecated APIs, schema violations, tool-specific errors

3) Load only the relevant reference file(s)

Primary failure-mode references:

  • references/insecure-workload-defaults.md
  • references/resource-starvation.md
  • references/network-exposure.md
  • references/privilege-sprawl.md
  • references/fragile-rollouts.md
  • references/api-drift.md

Supplemental references (only when needed):

  • references/deployment-patterns.md
  • references/stateful-patterns.md
  • references/job-patterns.md
  • references/daemonset-operator-patterns.md
  • references/security-hardening.md
  • references/observability.md
  • references/multi-tenancy.md
  • references/storage-and-state.md
  • references/helm-patterns.md
  • references/kustomize-patterns.md
  • references/validation-and-policy.md
  • references/examples-good.md
  • references/examples-bad.md
  • references/do-dont-patterns.md

Conditional Reference Retrieval (CRR) references (load only when the signal is detected):

  • references/conditional/eks-patterns.md for EKS, AWS, IRSA, EKS Pod Identity, AWS Load Balancer Controller, EBS/EFS CSI, Karpenter
  • references/conditional/gke-patterns.md for GKE, Autopilot, Workload Identity Federation for GKE, Dataplane V2, GCE Ingress, Config Sync
  • references/conditional/aks-patterns.md for AKS, Microsoft Entra Workload ID, Azure CNI, AGIC, Azure Disk/File/Blob CSI
  • references/conditional/openshift-patterns.md for OpenShift, OKD, ROSA, ARO, Routes, SCCs, OLM, oc
  • references/conditional/gitops-controllers.md for Argo CD, ApplicationSet, Flux, GitOps reconciliation, sync waves
  • references/conditional/observability-stacks.md for Prometheus Operator, ServiceMonitor, PodMonitor, OpenTelemetry, Loki, Grafana

Do not load multiple CRR files unless the task spans multiple detected platforms/tools.

Show full SKILL.md (143 more words)Show less

4) Propose fix path with explicit risk controls

For each fix, include:

  • why this addresses the failure mode
  • what could still go wrong at deploy time or runtime
  • guardrails (validation commands, policy checks, rollback path)

5) Generate implementation artifacts

When applicable, output:

  • Kubernetes manifests (YAML with security contexts, resource limits, labels)
  • Helm values/templates or Kustomize overlays
  • NetworkPolicies, RBAC resources, PodDisruptionBudgets
  • Policy rules (Kyverno/OPA) and admission controls

6) Validate before finalize

Always provide validation steps tailored to deployment method and risk tier:

  • kubectl apply --dry-run=server or kubectl diff
  • kubeconform for schema validation against target cluster version
  • cross-resource consistency check (label/selector/port alignment)
  • policy scan (PSS profile check, Kyverno/OPA audit) Never recommend direct production apply without reviewed diff and approval.

7) Output contract

Return:

  • assumptions and cluster version floor
  • selected failure mode(s)
  • chosen remediation and tradeoffs
  • validation/test plan
  • rollback/recovery notes (rollout undo, revision history, data safety)

© LukasNiessen, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 86 other files (references, assets) in the repository root of LukasNiessen/kubernetes-skill.

  • SKILL.md
  • .claude-plugin/marketplace.json
  • .github/CODEOWNERS
  • .github/FUNDING.yml
  • .github/PULL_REQUEST_TEMPLATE.md
  • .github/dependabot.yml
  • .github/workflows/deploy-docs.yml
  • .github/workflows/stale.yml
  • .github/workflows/validate.yml
  • .gitignore
  • CHANGELOG.md
  • CODE_OF_CONDUCT.md
  • CONTRIBUTING.md
  • LICENSE
  • PHILOSOPHY.md
  • README.md
  • assets/logo.png
  • … and 70 more

Open the folder on GitHubat commit 34f93c1

Compare with similar skills

KubeShark for Kubernetes next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

KubeShark for Kubernetes compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
KubeShark for Kubernetes this skillLukasNiessen/kubernetes-skill446—~1.2kAutomated safety check: PassMIT
Gke Manifest Generationgoogle/skills21k—~3.1kAutomated safety check: PassApache-2.0
Defender For Containersvinayaklatthe/microsoft-security-skills175—~2.1kAutomated safety check: PassMIT
Release Chartzabbix-community/helm-zabbix132—~1.5kAutomated safety check: PassApache-2.0
Kcli Cluster Deploymentkarmab/kcli653—~1.5kAutomated safety check: PassApache-2.0
Aks Deployment Skilltimothywarner/chatgptclass143—~916Automated safety check: PassCustom licence

Similar skills

  • Official

    Generates and updates secure, production-ready Kubernetes YAML manifests optimized for GKE Autopilot and GKE Standard clusters.

    21k GitHub stars~3.1k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Defender For Containers

    vinayaklatthe/microsoft-security-skills

    Guidance for Microsoft Defender for Containers — Kubernetes and container security across AKS, Azure Arc-enabled Kubernetes, EKS, GKE, and OpenShift.

    175 GitHub stars~2.1k tokensUpdated 3 mo ago
    DevOps & CloudAuto-check passed
  • Release Chart

    zabbix-community/helm-zabbix

    Cut and publish a new release of the Zabbix Helm chart in this repository, following the versioning rules and maintainer release process documented in CONTRIBUTING.md and CLAUDE.md (bump…

    132 GitHub stars~1.5k tokensUpdated 3 mo ago
    DevOps & CloudAuto-check passed
  • Guides deployment and management of Kubernetes clusters with kcli.

    653 GitHub stars~1.5k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Aks Deployment Skill

    timothywarner/chatgptclass

    Deploy and operate workloads on Azure Kubernetes Service (AKS) the safe way.

    143 GitHub stars~916 tokensUpdated 20 days ago
    DevOps & CloudAuto-check passed
  • Gke Batch Hpc

    google/skills

    Official

    Runs batch and HPC workloads on GKE, utilizing job queues and parallel processing.

    21k GitHub stars~1.4k tokensUpdated today
    DevOps & CloudAuto-check passed

Questions about KubeShark for Kubernetes

What does KubeShark for Kubernetes do?

Keeps Kubernetes manifests, Helm charts and policies grounded by diagnosing six failure modes, such as insecure defaults and API drift, and loading only matching references. The agent works top to bottom. It first records context: cluster version and distribution, namespace and environment criticality, workload type, deployment method, policy enforcement, cloud provider and CNI, and add-ons such as GitOps, observability, ingress or service mesh, stating assumptions when something is unknown.

When should I use KubeShark for Kubernetes?

KubeShark for Kubernetes fits situations like: generating Kubernetes manifests with secure, resource-aware defaults; reviewing manifests or Helm charts for risky settings; migrating manifests off deprecated APIs; working on EKS, GKE, AKS or OpenShift specific configuration.

How do I install KubeShark for Kubernetes in Claude Code?

Run `npx skills add LukasNiessen/kubernetes-skill --skill kubernetes-skill -a claude-code`. Or copy the skill folder (the LukasNiessen/kubernetes-skill repository) into .claude/skills/kubernetes-skill in your project. Claude Code loads it when a task matches its description.

How do I install KubeShark for Kubernetes in Codex?

Run `npx skills add LukasNiessen/kubernetes-skill --skill kubernetes-skill -a codex`. Or copy the skill folder (the LukasNiessen/kubernetes-skill repository) into .agents/skills/kubernetes-skill in your project. Codex loads it when a task matches its description.

Can I use KubeShark for Kubernetes in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LukasNiessen/kubernetes-skill --skill kubernetes-skill -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/kubernetes-skill, .gemini/skills/kubernetes-skill, .github/skills/kubernetes-skill and .opencode/skills/kubernetes-skill in your project.

What does KubeShark for Kubernetes need to run?

Going by SKILL.md and its folder, KubeShark for Kubernetes needs the command-line tools its instructions call (kubectl).

Does KubeShark for Kubernetes access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is KubeShark for Kubernetes safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does KubeShark for Kubernetes use?

KubeShark for Kubernetes is published under the MIT licence (from the LICENSE file in the skill folder). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does KubeShark for Kubernetes use?

About 1.2k tokens (SKILL.md is roughly 4.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 51k tokens, read only when the agent opens those files.

What are the alternatives to KubeShark for Kubernetes?

Skills that share tags, products or a category with KubeShark for Kubernetes: Gke Manifest Generation (google/skills, 21k stars), Defender For Containers (vinayaklatthe/microsoft-security-skills, 175 stars), Release Chart (zabbix-community/helm-zabbix, 132 stars) and Kcli Cluster Deployment (karmab/kcli, 653 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains KubeShark for Kubernetes?

LukasNiessen (a GitHub user) maintains it in LukasNiessen/kubernetes-skill, which has 446 GitHub stars. The repository was last updated on September 13, 2026.

Source: LukasNiessen/kubernetes-skill on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.