Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Prevent Kubernetes hallucinations by diagnosing and fixing failure modes: insecure workload defaults, resource starvation, network exposure, privilege sprawl, fragile rollouts, and API drift. Use when generating, reviewing, refactoring, or migrating manifests, Helm charts, Kustomize overlays, cluster policies, and platform-specific Kubernetes work for EKS, GKE, AKS, OpenShift, GitOps controllers, or observability stacks.
.claude/skills/lukasniessen-kubernetes-skill/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-02 | ✗→✓ | ▲ Improved | 168% | 0% |
| case-04 | ✗→✓ | ▲ Improved | 126% | 0% |
| case-05 | ✗→✓ | ▲ Improved | 126% | 0% |
| case-07 | ✗→✓ | ▲ Improved | 148% | 0% |
| case-08 | ✗→✓ | ▲ Improved | -14% | 0% |
Run this workflow top to bottom.
Record before writing manifests:
If unknown, state assumptions explicitly.
Select one or more based on user intent and risk:
Primary failure-mode references:
references/insecure-workload-defaults.mdreferences/resource-starvation.mdreferences/network-exposure.mdreferences/privilege-sprawl.mdreferences/fragile-rollouts.mdreferences/api-drift.mdSupplemental references (only when needed):
references/deployment-patterns.mdreferences/stateful-patterns.mdreferences/job-patterns.mdreferences/daemonset-operator-patterns.mdreferences/security-hardening.mdreferences/observability.mdreferences/multi-tenancy.mdreferences/storage-and-state.mdreferences/helm-patterns.mdreferences/kustomize-patterns.mdreferences/validation-and-policy.mdreferences/examples-good.mdreferences/examples-bad.mdreferences/do-dont-patterns.mdConditional Reference Retrieval (CRR) references (load only when the signal is detected):
references/conditional/eks-patterns.md for EKS, AWS, IRSA, EKS Pod Identity, AWS Load Balancer Controller, EBS/EFS CSI, Karpenterreferences/conditional/gke-patterns.md for GKE, Autopilot, Workload Identity Federation for GKE, Dataplane V2, GCE Ingress, Config Syncreferences/conditional/aks-patterns.md for AKS, Microsoft Entra Workload ID, Azure CNI, AGIC, Azure Disk/File/Blob CSIreferences/conditional/openshift-patterns.md for OpenShift, OKD, ROSA, ARO, Routes, SCCs, OLM, ocreferences/conditional/gitops-controllers.md for Argo CD, ApplicationSet, Flux, GitOps reconciliation, sync wavesreferences/conditional/observability-stacks.md for Prometheus Operator, ServiceMonitor, PodMonitor, OpenTelemetry, Loki, GrafanaDo not load multiple CRR files unless the task spans multiple detected platforms/tools.
For each fix, include:
When applicable, output:
Always provide validation steps tailored to deployment method and risk tier:
kubectl apply --dry-run=server or kubectl diffkubeconform for schema validation against target cluster versionNever recommend direct production apply without reviewed diff and approval.
Return:
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-15 | pass→pass | 14,049 | 20,718 | +47% | 1 | 1 | 0% | 2,355 | 4,694 | +99% | 0 | 0 | — |
case-20 | pass→pass | 12,800 | 15,462 | +21% | 1 | 1 | 0% | 2,464 | 3,758 | +53% | 0 | 0 | — |
case-21 | pass→pass | 12,194 | 15,722 | +29% | 1 | 1 | 0% | 2,327 | 3,993 | +72% | 0 | 0 | — |
case-01 | pass→pass | 13,306 | 11,954 | -10% | 1 | 1 | 0% | 2,111 | 3,086 | +46% | 0 | 0 | — |
case-02 | fail→pass | 8,677 | 12,714 | +47% | 1 | 1 | 0% | 1,306 | 3,498 | +168% | 0 | 0 | — |
case-03 | pass→pass | 13,754 | 17,089 | +24% | 1 | 1 | 0% | 2,178 | 4,405 | +102% | 0 | 0 | — |
case-04 | fail→pass | 8,208 | 9,315 | +13% | 1 | 1 | 0% | 1,225 | 2,773 | +126% | 0 | 0 | — |
case-05 | fail→pass | 8,354 | 10,995 | +32% | 1 | 1 | 0% | 1,403 | 3,171 | +126% | 0 | 0 | — |
case-06 | pass→pass | 11,645 | 13,535 | +16% | 1 | 1 | 0% | 1,886 | 3,503 | +86% | 0 | 0 | — |
case-07 | fail→pass | 7,591 | 10,686 | +41% | 1 | 1 | 0% | 1,248 | 3,092 | +148% | 0 | 0 | — |
case-08 | fail→pass | 13,432 | 3,991 | -70% | 1 | 1 | 0% | 2,046 | 1,750 | -14% | 0 | 0 | — |
case-09 | fail→pass | 11,164 | 2,730 | -76% | 1 | 1 | 0% | 1,786 | 1,600 | -10% | 0 | 0 | — |
case-10 | fail→pass | 17,087 | 6,350 | -63% | 1 | 1 | 0% | 2,791 | 2,295 | -18% | 0 | 0 | — |
case-11 | fail→pass | 13,610 | 4,800 | -65% | 1 | 1 | 0% | 2,136 | 1,776 | -17% | 0 | 0 | — |
case-12 | fail→pass | 12,083 | 10,738 | -11% | 1 | 1 | 0% | 1,849 | 2,870 | +55% | 0 | 0 | — |
case-13 | fail→pass | 12,052 | 5,360 | -56% | 1 | 1 | 0% | 2,066 | 2,063 | -0% | 0 | 0 | — |
case-14 | pass→pass | 14,300 | 12,807 | -10% | 1 | 1 | 0% | 2,259 | 3,150 | +39% | 0 | 0 | — |
case-16 | pass→pass | 10,026 | 10,855 | +8% | 1 | 1 | 0% | 1,687 | 2,397 | +42% | 0 | 0 | — |
case-17 | fail→pass | 11,001 | 5,464 | -50% | 1 | 1 | 0% | 1,747 | 2,086 | +19% | 0 | 0 | — |
case-18 | pass→pass | 8,878 | 16,737 | +89% | 1 | 1 | 0% | 1,584 | 4,009 | +153% | 0 | 0 | — |
case-19 | pass→pass | 8,419 | 4,605 | -45% | 1 | 1 | 0% | 1,320 | 1,938 | +47% | 0 | 0 | — |
case-22 | pass→fail | 8,382 | 13,199 | +57% | 1 | 1 | 0% | 1,525 | 3,330 | +118% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of +45 percentage points is the difference between those two pass rates over the 22 comparable cases. 1 case got worse with the skill loaded, and it is included in that figure.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.