escaping-containers-to-host

mukul975/escaping-containers-to-host · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Exploit privileged pods, host mounts, runC CVEs, and exposed Docker sockets to break out of a container and reach the underlying host during authorized container-security assessments.

SKILL.md

Files

This skill is a package of 5 files. Install with the command above, or download the folder.

  • 📄SKILL.md entry
  • 📁references
  • 📄api-reference.md 2.5 KB
  • 📄standards.md 2.3 KB
  • 📁scripts
  • ⚙️agent.py 6.7 KB
  • 📄LICENSE 11.0 KB

Related

  1. none · diegosouzapw bundle
    Detect container escape attempts using Falco, seccomp, and auditd, with rules for privileged containers, Docker socket access, and kernel module loading.
    54
    repo stars
  2. detecting-container-escape-attempts · mukul975 bundle
    Detect container escape attempts using runtime security tools like Falco, Sysdig, and custom seccomp/audit rules.
    24.6k
    repo stars
  3. auditing-kubernetes-rbac-privilege-escalation · mukul975 bundle
    Find over-permissive RBAC roles and service-account token abuse paths in Kubernetes using kubectl auth can-i, rbac-police, kubectl-who-can, and rakkess during authorized cluster security reviews.
    24.6k
    repo stars
  4. cloud-k8s · zhaoxuya520 bundle
    Authorized security assessment for cloud, container, and Kubernetes environments covering metadata SSRF, IAM misconfigurations, container escape paths, and cluster RBAC review.
    12.8k
    repo stars
  5. performing-container-escape-detection · mukul975 bundle
    Audits Kubernetes pods for container escape vectors by analyzing privileged mode, dangerous capabilities, host namespace sharing, and writable hostPath mounts using the Kubernetes Python client.
    24.6k
    repo stars
  6. detecting-privilege-escalation-in-kubernetes-pods · mukul975 bundle
    Detect and prevent privilege escalation in Kubernetes pods by monitoring security contexts, capabilities, and syscall patterns with Falco and OPA policies.
    24.6k
    repo stars

Frequently asked questions

How do I install the escaping-containers-to-host skill?

Run npx skillmds add mukul975/escaping-containers-to-host in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the escaping-containers-to-host skill do?

Exploit privileged pods, host mounts, runC CVEs, and exposed Docker sockets to break out of a container and reach the underlying host during authorized container-security assessments. It is listed under Security, DevOps & Infra, Containers & Kubernetes, Penetration Testing on SkillMD.

Is escaping-containers-to-host safe to use?

SkillMD's automated safety review verdict for this skill is CAUTION. Independent scanners report: SkillSpector: FAIL, Skill Scanner: PASS. Capability flags: executes scripts, makes network calls. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with escaping-containers-to-host?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is escaping-containers-to-host free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published escaping-containers-to-host?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.