fleet-audit skillA
fleet-audit is agent-read markdown (skill) from gke-labs/kube-agents: Publish the findings of an autonomous fleet audit as one continuously-rewritten GitHub issue per audit stream, and propose fixes as narrow remediation pull requests..
Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.
What the file says
# fleet-audit — Audit Findings to a Ledger Issue Every autonomous audit watchdog ends the same way: findings must reach a human somewhere durable, reviewable, and de-duplicated. This skill is that ending, in two tiers: - **Tier 1 — the ledger.** Each audit stream owns **exactly one open GitHub issue**, rewritten in full on every run and closed as completed when the fleet comes back clean. An operator watches one issue per stream instead of drowning in chat logs. - **Tier 2 — the fixes.** When a finding's remediation is a file in this repository, it travels separately as a **narrow pull request carrying only that fix**, linked back to the ledger. The split is the point. A report is not a change, so a report is not a pull request — and a fix is not a report, so it carries a real diff a reviewer can read in one screen. `./skills/fleet-audit/scripts/audit_report.py` owns every deterministic operation: credential minting, label creation, issue creation and rewriting, branch handling, staging, committing, pushing, pull-request creation, closing, the run-over-run delta, and every timestamp. **Your job is …
Read the whole file at its exact version.
How to install
mdr add gke-labs/kube-agents/fleet-audit@git:20260923.10a7ab8mdr add gke-labs/kube-agents/fleet-audit@sha256:043df3da296b9928Pin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.
[](https://markdownregistry.com/a/art_sgbm774frhgl4k7j)
1 badge views in 30 days
Versions
| version | committed | commit | size | audit | |
|---|---|---|---|---|---|
| git:20260923.10a7ab8 latest | 2026-09-23 | 10a7ab8 | 80,659 B | A | view · diff |
| git:20260919.0bd6fd8 | 2026-09-19 | 0bd6fd8 | 79,836 B | A | view · diff |
| git:20260918.240a0dd | 2026-09-18 | 240a0dd | 76,220 B | A | view · diff |
| git:20260918.0c70224 | 2026-09-18 | 0c70224 | 71,422 B | A | view · diff |
| git:20260917.1d4c7a3 | 2026-09-17 | 1d4c7a3 | 71,112 B | A | view · diff |
| git:20260915.fe062d3 | 2026-09-15 | fe062d3 | 65,564 B | A | view |
Audit of the latest version
- pass: Frontmatter block present
- pass: Frontmatter declares a name
- pass: Frontmatter declares a description
- pass: Size between 200 bytes and 200 KB (80659 bytes)
- pass: No zero-width or bidi control characters
- pass: No instruction hidden inside an HTML comment
- pass: No link to an exfiltration or paste host
- pass: No credential-shaped string
- pass: No instruction to send local credentials anywhere
- pass: No text hidden with inline styles
- pass: No prompt-injection phrasing
- pass: No curl or wget piped into a shell
- pass: No recursive delete of root, home or parent
- pass: No instruction to read or print local credentials
- pass: No base64 blob over 200 characters
- pass: No link to a raw IP address
- pass: No script tag
Source
gke-labs/kube-agents · 64 stars · license Apache-2.0 · pushed 2026-09-23 · branch main
API
GET https://markdownregistry.com/api/v1/artifacts/art_sgbm774frhgl4k7j GET https://markdownregistry.com/api/v1/resolve?ref=gke-labs/kube-agents/fleet-audit GET https://markdownregistry.com/api/v1/blob/043df3da296b99286c80f0d1812954b01df2a632204fd871377a8cbffcda2aed
Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.