技能低风险未认领

AKS Network Capture

Collects bounded packet captures from AKS nodes and Azure network configuration for wire-level evidence. WHEN: "capture packets on an AKS node", "take a pcap", "run tcpdump on AKS", "prove where packets drop". Use for explicit packet-capture intent after read-only diagnostics, not general AKS connectivity or ingress troubleshooting.

microsoftmicrosoft/aks-network-capture★ 3.1k更新于 2026年10月9日

说明

Quick Reference

Use Requires Safety
AKS pcap evidence kubectl; az for Azure evidence Bounded, pinned, least privilege

When to Use This Skill

Use for explicit packet capture after read-only checks, not generic connectivity failures.

MCP Tools

Azure MCP's AKS area provides cluster and node-pool metadata, not Kubernetes command execution or packet capture.

Host Capability Gate

Before executing the workflow, confirm that the host permits the required Bash or PowerShell execution, kubectl access to the bound cluster, az for Azure evidence, access to the bundled scripts, and an approved artifact destination. A governed Azure CLI tool alone does not establish that shell, Kubernetes commands, or artifact operations are supported.

If a required capability is unavailable or prohibited, state that capture execution is unavailable in this host. Analyze supplied, appropriately redacted evidence or give the operator a target-bound collection/capture plan; do not claim to have run it. Never route kubectl through Azure MCP, add an unapproved execution path, or bypass host policy. Host support does not replace the mutation and sensitive-data approvals below.

Run bundled scripts from the skill root only after this gate is satisfied.

Workflow/Steps

  1. Check host capabilities, then complete authorization and target binding. Capture intent is not mutation consent. Stop for separate approval before any debug-container fallback.
  2. Install Bash / PowerShell.
  3. Capture nodes or pods with Bash / PowerShell.
  4. Generate traffic if approved with Bash / PowerShell.
  5. Retrieve the exact run with Bash / PowerShell.
  6. Gather Azure evidence with Bash / PowerShell.

The ConfigMap runs run-capture.sh inside its pinned Linux image.

Error Handling

Error Action
Invalid input Correct it before retrying.
Missing/stale ConfigMap Run setup again.
Capture/retrieval failure Inspect Job logs; missing evidence is not success.

权限

声明检测
运行代码—powershellshell
安装—无
安装时运行脚本—无
网络—kubernetes.iolearn.microsoft.com
需要的凭据—RUN_TOKEN
工作区外的路径—无
智能体工具—无

检查

低风险 · 没有发现需要提醒的地方。

未经人工审核 · 已做规则检查;模型审核尚未开启。

另有 4 处低风险标记:常见命令之类,只记录、不提醒
  • 规则 · command_injectionscripts/collect-azure-network-info.sh:145
  • 规则 · command_injectionscripts/retrieve-captures.ps1:227
  • 规则 · command_injectionscripts/retrieve-captures.sh:243
  • 规则 · command_injectionscripts/run-capture.sh:88

文件13 个文件 · 77.4 KB

  • SKILL.md2.9 KB
references/1
  • capture-authorization.md1.4 KB
scripts/11
  • collect-azure-network-info.ps17.9 KB
  • collect-azure-network-info.shx7.0 KB
  • create-capture.ps111.5 KB
  • create-capture.shx12.4 KB
  • generate-test-traffic.ps15.4 KB
  • generate-test-traffic.shx6.1 KB
  • retrieve-captures.ps19.4 KB
  • retrieve-captures.shx8.1 KB
  • run-capture.shx2.4 KB
  • setup-capture-configmap.ps11.7 KB
  • setup-capture-configmap.shx1.2 KB

版本

  1. #11.0.1最新2026年10月10日