k8s-vind — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited k8s-vind (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Manage virtual Kubernetes clusters using kubectl-mcp-server's vind tools (14 tools).
vCluster enables running fully functional Kubernetes clusters as lightweight workloads inside a host cluster, combining multi-tenancy with strong isolation.
Use this skill when:
| Priority | Rule | Impact | Tools |
|---|---|---|---|
| 1 | Detect vCluster CLI first | CRITICAL | vind_detect_tool |
| 2 | Check cluster status before operations | HIGH | vind_status_tool |
| 3 | Connect before kubectl operations | HIGH | vind_connect_tool |
| 4 | Pause unused clusters to save resources | MEDIUM | vind_pause_tool |
| Task | Tool | Example |
|---|---|---|
| Detect vCluster | vind_detect_tool | vind_detect_tool() |
| List clusters | vind_list_clusters_tool | vind_list_clusters_tool() |
| Create cluster | vind_create_cluster_tool | vind_create_cluster_tool(name) |
| Connect to cluster | vind_connect_tool | vind_connect_tool(name) |
curl -L -o vcluster "https://github.com/loft-sh/vcluster/releases/latest/download/vcluster-$(uname -s | tr '[:upper:]' '[:lower:]')-$(uname -m)"
chmod +x vcluster && sudo mv vcluster /usr/local/bin/vind_detect_tool()vind_list_clusters_tool()vind_status_tool(name="my-vcluster", namespace="vcluster")vind_get_kubeconfig_tool(name="my-vcluster", namespace="vcluster")vind_logs_tool(name="my-vcluster", namespace="vcluster", tail=100)vind_create_cluster_tool(name="dev-cluster")
vind_create_cluster_tool(
name="dev-cluster",
namespace="dev",
kubernetes_version="v1.29.0",
connect=True
)
vind_create_cluster_tool(
name="custom-cluster",
set_values="sync.toHost.pods.enabled=true,sync.toHost.services.enabled=true"
)vind_delete_cluster_tool(name="dev-cluster")
vind_delete_cluster_tool(
name="dev-cluster",
namespace="dev",
delete_namespace=True
)vind_pause_tool(name="dev-cluster")vind_resume_tool(name="dev-cluster")vind_connect_tool(name="dev-cluster")
vind_connect_tool(
name="dev-cluster",
namespace="dev",
kube_config="~/.kube/vcluster-config"
)vind_disconnect_tool()vind_upgrade_tool(
name="dev-cluster",
kubernetes_version="v1.30.0"
)
vind_upgrade_tool(
name="dev-cluster",
values_file="new-values.yaml"
)vind_describe_tool(name="dev-cluster")vind_platform_start_tool()
vind_platform_start_tool(host="0.0.0.0", port=9898)vind_create_cluster_tool(name="dev", connect=True)
kubectl_apply(manifest="""
apiVersion: apps/v1
kind: Deployment
metadata:
name: my-app
namespace: default
spec:
replicas: 1
selector:
matchLabels:
app: my-app
template:
metadata:
labels:
app: my-app
spec:
containers:
- name: app
image: nginx:alpine
""")vind_create_cluster_tool(name="team-a", namespace="team-a-vcluster")
vind_create_cluster_tool(name="team-b", namespace="team-b-vcluster")
vind_list_clusters_tool()vind_pause_tool(name="dev")
vind_resume_tool(name="dev")For vCluster in Docker (vind) deployments, use --set values:
vind_create_cluster_tool(
name="docker-cluster",
set_values="experimental.docker.network=my-network,experimental.docker.ports[0].containerPort=80"
)1. vind_detect_tool()
2. vind_logs_tool(name="my-cluster", tail=200)
3. vind_status_tool(name="my-cluster")1. vind_disconnect_tool()
2. vind_connect_tool(name="my-cluster")
3. vind_get_kubeconfig_tool(name="my-cluster")1. vind_pause_tool(name="unused-cluster")
2. vind_delete_cluster_tool(name="old-cluster", delete_namespace=True)Install vCluster CLI:
curl -L -o vcluster "https://github.com/loft-sh/vcluster/releases/latest/download/vcluster-$(uname -s | tr '[:upper:]' '[:lower:]')-$(uname -m)"
chmod +x vcluster
sudo mv vcluster /usr/local/bin/
vcluster version~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.