auditing-kubernetes-rbac-privilege-escalation

mukul975/auditing-kubernetes-rbac-privilege-escalation · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Find over-permissive RBAC roles and service-account token abuse paths in Kubernetes using kubectl auth can-i, rbac-police, kubectl-who-can, and rakkess during authorized cluster security reviews.

SKILL.md

Files

This skill is a package of 5 files. Install with the command above, or download the folder.

  • 📄SKILL.md entry
  • 📁references
  • 📄api-reference.md 2.7 KB
  • 📄standards.md 1.8 KB
  • 📁scripts
  • ⚙️agent.py 5.7 KB
  • 📄LICENSE 11.0 KB

Related

  1. auditing-kubernetes-cluster-rbac · mukul975 bundle
    Audit Kubernetes RBAC configurations to identify overly permissive roles, wildcard permissions, dangerous bindings, service account abuse, and privilege escalation paths using kubectl, rbac-tool, KubiScan, and Kubeaudit.
    24.6k
    repo stars
  2. performing-kubernetes-penetration-testing · mukul975 bundle
    Systematically evaluates Kubernetes cluster security by simulating attacker techniques against the API server, kubelet, etcd, pods, RBAC, network policies, and secrets using tools like kube-hunter, Kubescape, and kube-bench.
    24.6k
    repo stars
  3. implementing-rbac-hardening-for-kubernetes · mukul975 bundle
    Harden Kubernetes Role-Based Access Control by implementing least-privilege policies, auditing role bindings, eliminating cluster-admin sprawl, and integrating external identity providers.
    24.6k
    repo stars
  4. escaping-containers-to-host · mukul975 bundle
    Exploit privileged pods, host mounts, runC CVEs, and exposed Docker sockets to break out of a container and reach the underlying host during authorized container-security assessments.
    24.6k
    repo stars
  5. gke-security · google bundle
    Hardens Google Kubernetes Engine (GKE) clusters with Workload Identity, Secret Manager, RBAC, Binary Authorization, Network Policies, and Pod Security Standards.
    14.4k
    repo stars
  6. cloud-k8s · zhaoxuya520 bundle
    Authorized security assessment for cloud, container, and Kubernetes environments covering metadata SSRF, IAM misconfigurations, container escape paths, and cluster RBAC review.
    12.8k
    repo stars

Frequently asked questions

How do I install the auditing-kubernetes-rbac-privilege-escalation skill?

Run npx skillmds add mukul975/auditing-kubernetes-rbac-privilege-escalation in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the auditing-kubernetes-rbac-privilege-escalation skill do?

Find over-permissive RBAC roles and service-account token abuse paths in Kubernetes using kubectl auth can-i, rbac-police, kubectl-who-can, and rakkess during authorized cluster security reviews. It is listed under Security, DevOps & Infra, Containers & Kubernetes, Penetration Testing on SkillMD.

Is auditing-kubernetes-rbac-privilege-escalation safe to use?

SkillMD's automated safety review verdict for this skill is CAUTION. Independent scanners report: SkillSpector: CAUTION, Skill Scanner: PASS. Capability flags: executes scripts, makes network calls, reads secrets. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with auditing-kubernetes-rbac-privilege-escalation?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is auditing-kubernetes-rbac-privilege-escalation free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published auditing-kubernetes-rbac-privilege-escalation?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.