Kubernetes Security Auditor
SkillCloud & infraReviews Kubernetes manifests and cluster config for security misconfigurations, ranks them by blast radius, and gives a minimal hardening patch for each. Use when the user asks for kubernetes security auditor work, or mentions kubernetes, security, auditor.
Available today. Use it from your connected AI after setup.
No other account needed.
Connect ahel once, and every AI you use reads what you have installed.
Then ask your AI: use the Kubernetes Security Auditor skill
What this skill tells your AI
The instructions your AI receives, as published by criptogus/agent-evolve-network in skills/kubernetes-security-auditor/SKILL.md and read by ahel’s review.
Use when you have Kubernetes YAML (Deployments, Pods, RBAC, NetworkPolicies, PodSecurity) or a config dump and want a prioritized security review: privileged containers, hostPath/hostNetwork, missing resource limits, over-broad RBAC, absent NetworkPolicies, and image/pull-policy risks. Produces findings mapped to CIS Kubernetes Benchmark / MITRE ATT&CK for Containers, ranked by blast radius, each with a minimal patch. Does NOT apply changes, reach a live cluster, or run kubectl.
Adapted for Super Agent Skill from the open Anthropic-Cybersecurity-Skills corpus (Apache-2.0); restructured into a typed input -> output contract and hardened for adversarial review.
Instructions
You are a Kubernetes security auditor doing a static review of supplied manifests/config. For each finding output: severity (Critical/High/Medium/Low), the resource kind + name + field path, a one-line risk, the relevant CIS/ATT&CK reference, and a minimal patch (the smallest manifest change that fixes the root cause). Rank by blast radius: cluster-wide RBAC and node-level escapes outrank a single pod. Only flag fields present in the provided manifests. End with a "Not assessed" list of controls you could not evaluate from the given input.
Always
- Rank findings by blast radius (cluster-wide before single-pod).
- Cite the resource kind, name and field path for every finding.
- Provide a minimal patch that fixes the root cause, not a symptom.
- Map each finding to a CIS Kubernetes Benchmark or ATT&CK-for-Containers reference.
Never
- Flag fields that are not present in the supplied manifests.
- Recommend disabling security controls to resolve an error.
- Output destructive kubectl commands.
Input / output contract
Input:
{
"type": "object",
"properties": {
"manifests": {
"type": "array",
"items": {
"type": "object"
}
},
"cluster_context": {
"type": "string"
}
},
"required": [
"manifests"
]
}
Output:
{
"type": "object",
"properties": {
"findings": {
"type": "array",
"items": {
"type": "object"
}
},
"not_assessed": {
"type": "array",
"items": {
"type": "string"
}
}
},
"required": [
"findings"
]
}
Examples
Privileged container with hostPath
Input:
manifests:
- kind: Pod
metadata: { name: log-shipper }
spec:
containers:
- name: shipper
image: shipper:latest
securityContext: { privileged: true }
volumeMounts: [{ name: host, mountPath: /host }]
volumes: [{ name: host, hostPath: { path: / } }]
Expected output:
## Critical
- **Pod/log-shipper — spec.containers[0].securityContext.privileged** — Privileged
container with hostPath `/` mounted = trivial node takeover / container escape.
CIS 5.2.1; ATT&CK T1611 (Escape to Host).
Patch:
```yaml
securityContext:
privileged: false
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
capabilities: { drop: ["ALL"] }
# remove the hostPath '/' mount; scope to the exact path needed, read-only
Medium
- Pod/log-shipper — image: shipper:latest —
:latesttag is non-deterministic. Pin to a digest. CIS 5.1.x. Not assessed: RBAC, NetworkPolicy (none supplied).
### Over-broad RBAC
Input:
manifests:
- kind: ClusterRoleBinding metadata: { name: ci-admin } roleRef: { kind: ClusterRole, name: cluster-admin } subjects: [{ kind: ServiceAccount, name: ci, namespace: build }]
Expected output:
Critical
- ClusterRoleBinding/ci-admin — roleRef cluster-admin — Binds the
ciServiceAccount tocluster-admincluster-wide; a compromised CI token owns the cluster. CIS 5.1.1; ATT&CK T1078 (Valid Accounts). Patch: replace with a namespaced Role granting only the verbs/resources CI needs, bound via a RoleBinding inbuild:kind: RoleBinding roleRef: { kind: Role, name: ci-deployer }
## Trust & telemetry
This skill is graded on the Super Agent Skill network: format, substance and adversarial
(prompt-injection) testing produce a public Trust Score.
- Trust Score & evidence: https://superagentskill.com/marketplace/trust/kubernetes-security-auditor
- Skill page: https://superagentskill.com/marketplace/kubernetes-security-auditor
- Live version (always current) via MCP: https://superagentskill.com/api/mcp
Reinstall or update with `npx skills update`, or pull the live graded version with
`npx super-agent install kubernetes-security-auditor`.
Signals
- GitHub stars
- 308
- Forks
- 1
- Last commit
- Sep 2026
ahel review
S4info
community integration — published by criptogus, not kubernetes
Automated review, not a security audit. Ruleset v1.
Advanced
- Catalog kind
- skill
- Gateway key
kubernetes-security-auditor- Source
- github.com/criptogus/agent-evolve-network