All skills
hardw00t avatar

/container-security

@f9bb3b2

Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and runtime monitoring (Falco/Tetragon). Use when scanning Docker/OCI images, auditing K8s clusters, reviewing Dockerfiles, diffing SBOMs across releases, analyzing RBAC, or assessing container runtime posture. Triggers on requests involving Trivy, Grype, Syft, Kubescape, kube-bench, Falco, container escapes, or CIS Docker/K8s benchmarks.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/container-security

This session only. Nothing lands on disk.

templatesassessment_report_template.md

≈523 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Container Security Assessment Report Template

Use this template to produce the deliverable at the end of a container security engagement. Fill in each section; delete any that don't apply.

Executive Summary

  • Assessment date: YYYY-MM-DD
  • Scope: X images, Y clusters, Z namespaces
  • Critical: N | High: N | Medium: N | Low: N
  • CIS compliance score: Z%
  • New CVEs since prior baseline (SBOM diff): N

Image Scan Results

<image>@<digest>

CVE Severity CVSS Package Current Fixed

Scanners run: Trivy vX.Y, Grype vX.Y, Syft vX.Y. SBOM attested: yes/no (cosign).

SBOM Diff (if applicable)

Baseline: <prior-digest> -> Current: <current-digest>

  • Added packages: N
  • Removed packages: N
  • Version-bumped: N
  • Newly-introduced CVEs: N (list by severity)
  • Newly-fixed CVEs: N

Kubernetes Findings

CIS Benchmark (kube-bench vX.Y, CIS K8s vX.Y)

Section Pass Fail Score
Control plane
Worker nodes
Policies

RBAC

  • Over-permissioned principals: N
  • Shortest path(s) to cluster-admin: ...

NetworkPolicy coverage

  • Namespaces without default-deny: ...
  • Over-permissive egress rules: ...

Runtime (Falco/Tetragon)

  • Alerts in window: N
  • Highest-severity events: ...

Container Escape Testing

(Only if engagement scope included active testing.)

  • Vectors tested: ...
  • Successful escapes: ...
  • Detected by runtime sensor: yes/no per vector

Critical Findings (top 10)

  1. [CRITICAL] ...
  2. [HIGH] ...

Recommendations

  1. Patch / rebuild affected images
  2. Enforce Pod Security Standards (restricted)
  3. Default-deny NetworkPolicy per namespace
  4. Remove cluster-admin bindings for workloads
  5. Enable runtime monitoring (Falco or Tetragon)
  6. Pin images by digest + require signed SBOM attestation

Appendix

  • Raw scanner outputs: evidence/
  • Schema: schemas/finding.json

Source: SKILL.md on GitHub

1 alert16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The skill is a legitimate security toolset for auditing Kubernetes and container environments. It provides instructions and workflows for industry-standard scanners such as Trivy, Grype, and Kubescape, and includes documented proof-of-concept scripts for container escapes intended for authorized security assessments and labs.

  • Socket16d

    3 alerts: gptSecurity

  • Snyk16d

    Risk: MEDIUM · 1 issue

  • Runlayer7mo

    1/1 file flagged

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/container-security