More screenshots

    Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIGitHub CopilotGitHub CopilotGemini CLIGemini CLI+20 more

    Kubernetes Manifest Reviewer

    1

    You `kubectl apply` a manifest that worked in staging, and production pods immediately start getting OOMKilled because...

    Free

    4 installsSecurity scanned
    kubernetes-manifest-reviewer

    kubernetes-manifest-reviewer

    Example session with this skill installed

    "Review my k8s/ manifests before I apply to production"

    • Read your context and instructions
    • Compiled the kubernetes-manifest-reviewer
    • Generated the document

    "Kubernetes Manifest Review Report — 8 files, 12 resources

    Summary: Files reviewed: 8 | Issues: 3 critical, 5 high, 4 medium, 2 low
    Overall risk: HIGH

    Critical Issues (must fix before deploy):

    1. [deployment.yaml:15] Container runs as root — runAsNonRoot: true missing from securityContext
    2. [deployment.yaml:8] Image uses :latest tag — pin to specific version for reproducible deployments
    3. [secret.yaml:6] Password hardcoded in env var — use Kubernetes Secret with secretKeyRef

    High-Priority Issues

    1. [deployment.yaml:20] No resource limits set — pods will compete for resources, OOMKilled under load
    2. [deployment.yaml:25] Missing livenessProbe — unhealthy pods will keep receiving traffic
    3. [deployment.yaml:30] replicas: 1 in production — single pod failure causes downtime
    4. [ingress.yaml:10] No TLS configured — traffic served over HTTP
    5. [deployment.yaml:8] Missing readOnlyRootF

    kubernetes-manifest-reviewer.pdf

    PDF · document

    Generated

    Example file from a real run - the skill writes it into your workspace.

    Connects securely to your tools. The creator never sees your data.

    About this skill

    The Problem

    You kubectl apply a manifest that worked in staging, and production pods immediately start getting OOMKilled because there are no resource limits. Or a container runs as root with privileged: true because nobody reviewed the securityContext. Or the Ingress has no TLS and your security audit flags it as a critical finding. Kubernetes manifests are 200-line YAML files that silently encode security decisions — and most teams review them by scrolling and hoping.

    What You Get

    • Pod security audit — flags containers running as root, privileged mode, missing readOnlyRootFilesystem, missing seccompProfile, dangerous capabilities (NET_ADMIN, SYS_ADMIN), and missing capabilities.drop: ["ALL"]
    • Image security scanning — catches :latest tag usage, missing registry prefixes, images from untrusted registries, and missing imagePullPolicy for mutable tags
    • Resource limit enforcement — validates that all containers have CPU/memory requests AND limits, catches requests exceeding limits, flags unrealistic values, and recommends LimitRange/ResourceQuota at namespace level
    • Reliability gap detection — identifies missing livenessProbe/readinessProbe, single-replica Deployments in production, missing PodDisruptionBudgets, missing podAntiAffinity rules, and missing rollout strategies
    • Secret management audit — catches hardcoded passwords in env vars, Secrets without proper type designation, ConfigMaps containing sensitive data, and recommends secretKeyRef patterns
    • Network security review — flags Ingress resources without TLS, LoadBalancer Services without IP whitelisting, missing NetworkPolicy resources, and missing ssl-redirect annotations

    Why This Beats Prompting It Yourself

    You can ask "check this manifest" for a single file. But production deployments involve 15+ resources — Deployments, Services, ConfigMaps, Secrets, Ingresses, PDBs — and the most dangerous issues are cross-resource mismatches: a Service selector that doesn't match any Pod labels, a ConfigMap reference that points to a key that doesn't exist, or a PVC that uses a StorageClass your cluster doesn't have. This skill performs the full cross-resource validation that individual file review misses.

    Example Session

    You: "Review my k8s/ manifests before I apply to production"

    Agent: "Kubernetes Manifest Review Report — 8 files, 12 resources

    Summary: Files reviewed: 8 | Issues: 3 critical, 5 high, 4 medium, 2 low Overall risk: HIGH

    Critical Issues (must fix before deploy):

    1. [deployment.yaml:15] Container runs as root — runAsNonRoot: true missing from securityContext
    2. [deployment.yaml:8] Image uses :latest tag — pin to specific version for reproducible deployments
    3. [secret.yaml:6] Password hardcoded in env var — use Kubernetes Secret with secretKeyRef

    High-Priority Issues:

    1. [deployment.yaml:20] No resource limits set — pods will compete for resources, OOMKilled under load
    2. [deployment.yaml:25] Missing livenessProbe — unhealthy pods will keep receiving traffic
    3. [deployment.yaml:30] replicas: 1 in production — single pod failure causes downtime
    4. [ingress.yaml:10] No TLS configured — traffic served over HTTP
    5. [deployment.yaml:8] Missing readOnlyRootFilesystem — container can write to filesystem

    Medium-Priority Issues:

    1. [deployment.yaml:35] Missing PodDisruptionBudget — node maintenance will cause downtime
    2. [service.yaml:8] Missing app.kubernetes.io/* labels — breaks monitoring and service mesh
    3. [configmap.yaml:5] Contains API key — should be a Secret, not a ConfigMap
    4. [deployment.yaml:40] No topologySpreadConstraints — all pods may land on same node

    Recommendation: Fix 3 critical + 5 high issues before applying to production."

    Use Cases

    • Pre-deployment review before applying manifests to any cluster (dev, staging, production)
    • PR review for changes that introduce or modify Kubernetes resources
    • Debugging deployment failures caused by manifest misconfigurations
    • Onboarding new developers who are writing their first Kubernetes manifests
    • Security audit of existing deployments to establish a baseline

    Known Limitations

    This skill reviews manifest files statically — it cannot detect runtime issues like network connectivity, DNS resolution, or storage class availability. API version deprecation warnings depend on knowing your cluster version; ask the user for their K8s version if not provided. Does not replace tools like OPA/Gatekeeper or Kyverno for policy enforcement at admission time.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    4 installs

    Downloaded by developers to date

    Free forever

    No account required to browse

    Trust & safety

    Security scanned

    Verified clean 4 months ago

    • Free to download with an account

    Listed4 months ago
    Updated9 days ago

    What's inside

    Frequently Asked Questions