Iac Security Review
OWASP/secure-agent-playbook
Security review of Infrastructure-as-Code (Terraform, Kubernetes, CloudFormation).
Review Kubernetes NetworkPolicies — what is actually permitted to reach a workload, and whether the answer can be trusted.
$ npx skills add automateyournetwork/netclaw --skill k8s-network-policy -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install automateyournetwork/netclaw k8s-network-policy --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/workspace/skills/k8s-network-policy .claude/skills/k8s-network-policy && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "k8s-network-policy" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/k8s-network-policy into .claude/skills/k8s-network-policy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "k8s-network-policy", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/k8s-network-policyType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add automateyournetwork/netclaw --skill k8s-network-policy -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install automateyournetwork/netclaw k8s-network-policy --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .agents/skills && cp -r skills-src/workspace/skills/k8s-network-policy .agents/skills/k8s-network-policy && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "k8s-network-policy" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/k8s-network-policy into .agents/skills/k8s-network-policy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "k8s-network-policy", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add automateyournetwork/netclaw --skill k8s-network-policy -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install automateyournetwork/netclaw k8s-network-policy --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/workspace/skills/k8s-network-policy .cursor/skills/k8s-network-policy && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "k8s-network-policy" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/k8s-network-policy into .cursor/skills/k8s-network-policy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "k8s-network-policy", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/automateyournetwork/netclaw.git --path workspace/skills/k8s-network-policy--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add automateyournetwork/netclaw --skill k8s-network-policy -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install automateyournetwork/netclaw k8s-network-policy --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/workspace/skills/k8s-network-policy .gemini/skills/k8s-network-policy && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "k8s-network-policy" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/k8s-network-policy into .gemini/skills/k8s-network-policy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "k8s-network-policy", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install automateyournetwork/netclaw k8s-network-policyInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add automateyournetwork/netclaw --skill k8s-network-policy -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .github/skills && cp -r skills-src/workspace/skills/k8s-network-policy .github/skills/k8s-network-policy && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "k8s-network-policy" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/k8s-network-policy into .github/skills/k8s-network-policy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "k8s-network-policy", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add automateyournetwork/netclaw --skill k8s-network-policy -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install automateyournetwork/netclaw k8s-network-policy --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/workspace/skills/k8s-network-policy .opencode/skills/k8s-network-policy && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "k8s-network-policy" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/k8s-network-policy into .opencode/skills/k8s-network-policy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "k8s-network-policy", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
k8s-network-policyReview Kubernetes NetworkPolicies — what is actually permitted to reach a workload, and whether the answer can be trusted.
K8s Network Policy is an agent skill from automateyournetwork/netclaw. Review Kubernetes NetworkPolicies — what is actually permitted to reach a workload, and whether the answer can be trusted. Use when asked what can talk to a pod, whether a namespace is restricted, why traffic is being blocked, or for any security review of cluster network segmentation.
Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering Container orchestration and Security review. It works with Kubernetes. The repository describes itself as: An AI agent that claws through your network. The licence is Apache-2.0.
2 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit aa90e7d. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
kubectlFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use kubectl, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
K8s Network Policy loads about 1.5k tokens when it runs. Until then it costs about 76 tokens; SKILL.md has 692 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from automateyournetwork/netclaw at commit aa90e7d, republished under its Apache-2.0 licence (© automateyournetwork). 692 words, ~1,488 tokens.
.claude/skills/k8s-network-policy/SKILL.md (or your agent's skills folder).k8s-mcp — vendored third-party (containers/kubernetes-mcp-server v0.0.66, Apache-2.0), a pinned
static Go binary. 7 tools, strictly read-only, Secrets denied.
Kubernetes is default-allow. A namespace with zero policies permits everything, in both directions.
So "no policies found" is not a neutral observation — it is a finding, and reporting it without the consequence invites exactly the wrong conclusion. Someone reading "no policies" while thinking about security will hear "nothing to worry about". The opposite is true.
Always say the consequence: "No NetworkPolicy applies to this workload, so all ingress and egress traffic is permitted."
This is the one that gets people, and this server makes it worse.
Given a credential without cluster-wide list permission, the adopted server does not return an error. It silently rewrites your cluster-wide query to a single namespace and hands back that result with no caveat. Reproduced against a live cluster:
raw kubectl → Forbidden: cannot list networkpolicies at the cluster scope
this server → success, one policy ← the cluster actually had twoFor a security review that is an audit lie: "no policy restricts this pod" when the truth is "I could not see them".
Step 1 — confirm scope before you trust anything.
kubectl --kubeconfig $K8S_KUBECONFIG auth can-i list networkpolicies --all-namespacesyes → cluster-wide answers are trustworthy. Proceed.no → stop treating empty results as absence. Any answer you give is namespace-scoped at best, and
you must say so explicitly.The supported deployment uses a dedicated cluster-wide-read ServiceAccount precisely so this returns yes
and the narrowing branch never executes. If it returns no, the deployment is misconfigured — say that
rather than working around it.
Step 2 — list the policies.
resources_list({"apiVersion": "networking.k8s.io/v1", "kind": "NetworkPolicy"})
resources_list({"apiVersion": "networking.k8s.io/v1", "kind": "NetworkPolicy", "namespace": "app1"})Step 3 — report selectors, policy types and rules, not merely that a policy exists. "There is a policy"
tells a reviewer nothing about what is permitted. Give the podSelector, the policyTypes
(Ingress/Egress), and the actual from/to rules.
Step 4 — state the scope you actually queried, and which cluster answered. An operator with several clusters must never have to guess.
| Cause | How to tell | How to say it |
|---|---|---|
| Permission insufficient | Step 1 returned no | "Scope could not be established — this is not evidence that no policies exist" |
| Namespace does not exist | namespaces_list does not contain it | "No such namespace" — not "no policies" |
| Namespace exists but is empty | it is in namespaces_list | "No policies in this namespace, so all traffic there is permitted" |
| Selector matched nothing | you passed a label selector | "No match for <selector>" — and show the selector, so a typo is visible |
| CRD not installed | GVK resolution error | "Cilium/Calico policies are not installed on this cluster" — a real error, distinguishable |
| Cluster unreachable | transport failure | "The cluster could not be reached" — never "no policies" |
A typo'd selector and a genuine non-match are identical over the wire — both return HTTP 200 with an empty list. Showing the selector you used is the only thing that lets a reader spot the difference.
A namespace-scoped policy list is not a complete picture of what can reach a workload. Policies in other
namespaces, and cluster-scoped CRD policies (Cilium CiliumClusterwideNetworkPolicy, Calico
GlobalNetworkPolicy), also apply. Say so unless cluster-wide scope was confirmed and CRDs were checked.
kubeshark-traffic shows packets that flowed. This shows what is declared. They answer different
questions and are constantly confused:
When both are used, report them as two kinds of evidence, never as one conclusion.
| Want to… | Use |
|---|---|
| See actual packets | kubeshark-traffic — observed traffic, not declared config |
| Workload metrics | prometheus, grafana |
| Build a lab | containerlab, gns3, cml |
| Service/ingress path | k8s-service-path |
| Pod inventory | k8s-workload-inventory |
| Change anything | nothing here. Strictly read-only; no mutation is reachable |
© automateyournetwork, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in workspace/skills/k8s-network-policy of automateyournetwork/netclaw.
Open the folder on GitHubat commit aa90e7d
K8s Network Policy next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| K8s Network Policy this skillautomateyournetwork/netclaw | 676 | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | |
| Iac Security ReviewOWASP/secure-agent-playbook | 188 | — | ~694 | Automated safety check: Pass | CC-BY-4.0 | |
| Infrastructure Auditforefy/.context | 152 | — | ~3.7k | Automated safety check: Notes | MIT | |
| Operate Kubernetes Toolchaincyberful/cyberful | 135 | — | ~898 | Automated safety check: Pass | AGPL-3.0 | |
| Audit Cloud Native Securitycyberful/cyberful | 135 | — | ~852 | Automated safety check: Pass | AGPL-3.0 | |
| Performing Kubernetes Etcd Security Assessmentmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 |
OWASP/secure-agent-playbook
Security review of Infrastructure-as-Code (Terraform, Kubernetes, CloudFormation).
forefy/.context
Comprehensive infrastructure security audit framework for IaC, Docker, Kubernetes, and cloud configurations.
cyberful/cyberful
Operate kubectl, kube-bench, Trivy, Prowler, and manifest/runtime evidence for advanced Kubernetes security assessment.
cyberful/cyberful
Route a cloud-native security audit across effective IAM, infrastructure as code, build and release paths, containers, Kubernetes, serverless workloads, secrets, event sources, and control-plane…
mukul975/Anthropic-Cybersecurity-Skills
Assesses the security posture of the etcd cluster backing Kubernetes: encryption at rest, TLS peer and client transport, access control, backup encryption, and network isolation.
sickn33/agentic-awesome-skills
Harden Docker/container images and runtime deployments with secure base images, non-root users, CVE scanning, SBOM/signing, seccomp/AppArmor, and Kubernetes pod security controls.
automateyournetwork/netclaw
Entry point for designing EVE-NG network labs: classifies the request, gathers missing requirements, proposes options and validates the resulting topology.
automateyournetwork/netclaw
Deploys Cisco ACI policy changes only behind an approved ServiceNow Change Request, capturing pre and post-change fault baselines and rolling back automatically on a fault delta.
automateyournetwork/netclaw
Runs a phased health audit of a Cisco ACI fabric through MCP tools: node status, links, tenant and policy review, faults and endpoint learning.
automateyournetwork/netclaw
Validate Arista EOS network state against ANTA's pre-built 208-test catalogue, with structured pass/fail verdicts.
automateyournetwork/netclaw
Arista CloudVision Portal (CVP) automation via REST API — device inventory, events, connectivity monitoring, tag management (4 tools).
automateyournetwork/netclaw
AWS CloudWatch monitoring — metrics, alarms, log queries, VPC flow log analysis, network performance.
Works with
Categories
Review Kubernetes NetworkPolicies — what is actually permitted to reach a workload, and whether the answer can be trusted. K8s Network Policy is an agent skill from automateyournetwork/netclaw. Review Kubernetes NetworkPolicies — what is actually permitted to reach a workload, and whether the answer can be trusted.
K8s Network Policy fits situations like: asked what can talk to a pod; whether a namespace is restricted; why traffic is being blocked; for any security review of cluster network segmentation.
Run `npx skills add automateyournetwork/netclaw --skill k8s-network-policy -a claude-code`. Or copy the skill folder (workspace/skills/k8s-network-policy in automateyournetwork/netclaw) into .claude/skills/k8s-network-policy in your project. Claude Code loads it when a task matches its description.
Run `npx skills add automateyournetwork/netclaw --skill k8s-network-policy -a codex`. Or copy the skill folder (workspace/skills/k8s-network-policy in automateyournetwork/netclaw) into .agents/skills/k8s-network-policy in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add automateyournetwork/netclaw --skill k8s-network-policy -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/k8s-network-policy, .gemini/skills/k8s-network-policy, .github/skills/k8s-network-policy and .opencode/skills/k8s-network-policy in your project.
Going by SKILL.md and its folder, K8s Network Policy needs the command-line tools its instructions call (kubectl).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
K8s Network Policy is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with K8s Network Policy: Iac Security Review (OWASP/secure-agent-playbook, 188 stars), Infrastructure Audit (forefy/.context, 152 stars), Operate Kubernetes Toolchain (cyberful/cyberful, 135 stars) and Audit Cloud Native Security (cyberful/cyberful, 135 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
automateyournetwork (a GitHub user) maintains it in automateyournetwork/netclaw, which has 676 GitHub stars. The repository holds 120 skills in this directory. The repository was last updated on October 9, 2026.
Source: automateyournetwork/netclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.