All skills
hardw00t avatar

/container-security

@f9bb3b2

Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and runtime monitoring (Falco/Tetragon). Use when scanning Docker/OCI images, auditing K8s clusters, reviewing Dockerfiles, diffing SBOMs across releases, analyzing RBAC, or assessing container runtime posture. Triggers on requests involving Trivy, Grype, Syft, Kubescape, kube-bench, Falco, container escapes, or CIS Docker/K8s benchmarks.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/container-security

This session only. Nothing lands on disk.

workflowsimage_scan.md

≈514 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Workflow: Build-Time Image Vulnerability Scan

Use during CI on every built image, or ad-hoc on registry images.

Inputs

  • Image reference (registry/repo:tag or sha256: digest)
  • Severity gate (default: fail on CRITICAL)
  • Output dir for artifacts

Steps

  1. Resolve to digest (avoid tag-race):

    DIGEST=$(crane digest "$IMAGE")
    REF="${IMAGE%%:*}@${DIGEST}"
  2. Parallel scanners (run concurrently — they don't interfere):

    trivy image -f json -o trivy.json "$REF" &
    grype "$REF" -o json > grype.json &
    syft "$REF" -o cyclonedx-json=sbom.cdx.json &
    syft "$REF" -o syft-json=sbom.syft.json &
    hadolint -f json Dockerfile > hadolint.json &
    wait
  3. Secret + misconfig sweep (Trivy extra scanners):

    trivy image --scanners secret,misconfig -f json -o trivy-secrets.json "$REF"
  4. Consensus merge: intersect CVE IDs from Trivy and Grype; flag Trivy-only or Grype-only findings for manual confirmation (DB staleness is the usual cause).

  5. Severity gate:

    jq '[.Results[].Vulnerabilities[]? | select(.Severity=="CRITICAL")] | length' \
      trivy.json

    Fail CI if >0 and not in exceptions.yaml.

  6. Attach SBOM attestation (if cosign configured):

    cosign attest --predicate sbom.cdx.json --type cyclonedx "$REF"
  7. Emit findings as schemas/finding.json records with evidence.scanner, affected.image_digest, cve, cvss, fixed_version populated.

Parallelism

Operation Parallel?
Trivy + Grype + Syft + Hadolint on same image Yes
Multiple images / tags Yes (one sub-agent per image)
Cosign attestation Sequential (needs SBOM)
CVE consensus merge Sequential (needs scanner output)

Exit criteria

  • All scanners completed (or timeout with partial results recorded)
  • Severity gate evaluated
  • SBOM stored alongside image for future sbom_diff comparisons

Source: SKILL.md on GitHub

1 alert16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The skill is a legitimate security toolset for auditing Kubernetes and container environments. It provides instructions and workflows for industry-standard scanners such as Trivy, Grype, and Kubescape, and includes documented proof-of-concept scripts for container escapes intended for authorized security assessments and labs.

  • Socket16d

    3 alerts: gptSecurity

  • Snyk16d

    Risk: MEDIUM · 1 issue

  • Runlayer7mo

    1/1 file flagged

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/container-security