All skills
hardw00t avatar

/container-security

@f9bb3b2

Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and runtime monitoring (Falco/Tetragon). Use when scanning Docker/OCI images, auditing K8s clusters, reviewing Dockerfiles, diffing SBOMs across releases, analyzing RBAC, or assessing container runtime posture. Triggers on requests involving Trivy, Grype, Syft, Kubescape, kube-bench, Falco, container escapes, or CIS Docker/K8s benchmarks.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/container-security

This session only. Nothing lands on disk.

workflowsnetwork_policy_review.md

≈570 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Workflow: NetworkPolicy Coverage Review

Identify namespaces without default-deny, over-permissive ingress/egress rules, and gaps between intended and actual pod connectivity.

Steps

  1. Inventory:

    kubectl get networkpolicies -A -o json > netpol.json
    kubectl get ns -o json > ns.json
    kubectl get pods -A -o json > pods.json
  2. Default-deny coverage: For each namespace, confirm at least one NetworkPolicy with an empty podSelector and no rules (ingress-deny-all) plus one with egress deny.

    jq -r '
      .items[]
      | select(
          (.spec.podSelector // {}) == {}
          and (.spec.policyTypes | index("Ingress"))
          and ((.spec.ingress // []) | length == 0)
        )
      | .metadata.namespace
    ' netpol.json | sort -u > ns_with_default_deny_ingress.txt
  3. Over-permissive rules:

    • Ingress from 0.0.0.0/0 on non-gateway pods
    • Egress to 0.0.0.0/0 without destination port restrictions
    • namespaceSelector: {} + podSelector: {} (any pod from any ns)
  4. Enforcement validation — actually attempt the connectivity:

    kubectl run netshoot --rm -it --image=nicolaka/netshoot -n <src-ns> \
      -- curl -m 3 <dst-pod-ip>:<port>

    Or use kubectl netpol-check (if Cilium) / np-viewer.

  5. Cross-check CNI enforcement: NetworkPolicies only take effect if the CNI enforces them (Calico, Cilium, Weave). Flannel alone does not.

  6. Egress surface:

    • DNS policy — pods resolving external names via cluster DNS?
    • Any pod with egress to metadata service (169.254.169.254)?
    • TLS SNI inspection or L7 policy in place (Cilium, Istio)?

Tools

Tool Use
cyctl netpol Cilium policy inspection
np-viewer Visualize effective policy
kubescape NetworkPolicy-specific controls
inspektor gadget Live traffic observation (advise-mode → policy)

Parallelism

  • Inventory fetches: parallel
  • Per-namespace evaluation: parallel
  • Connectivity probes: parallel (bounded concurrency, avoid DoS)

Source: SKILL.md on GitHub

1 alert16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The skill is a legitimate security toolset for auditing Kubernetes and container environments. It provides instructions and workflows for industry-standard scanners such as Trivy, Grype, and Kubescape, and includes documented proof-of-concept scripts for container escapes intended for authorized security assessments and labs.

  • Socket16d

    3 alerts: gptSecurity

  • Snyk16d

    Risk: MEDIUM · 1 issue

  • Runlayer7mo

    1/1 file flagged

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/container-security