Agent skill

Container Audit

by briiirussell in briiirussell/cybersecurity-skills

Audit container images, Dockerfiles, and Kubernetes manifests for misconfigurations, excessive privileges, exposed secrets, and runtime risks.

MITAuto-check: notesDevOps & Cloud

Install Container Audit

skills CLI
$ npx skills add briiirussell/cybersecurity-skills --skill container-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install briiirussell/cybersecurity-skills container-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/briiirussell/cybersecurity-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/container-audit .claude/skills/container-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
container-audit
GitHub stars
413
Token cost
~2.5k tokens
SKILL.md length
876 words
Files
1
Skills in repo
25
Repo updated
First seen
Licence
MIT

At a glance

Audit container images, Dockerfiles, and Kubernetes manifests for misconfigurations, excessive privileges, exposed secrets, and runtime risks.

  • Works in 4 steps: Inventory the surface — Dockerfiles,… → Identify the runtime — vanilla K8s, EKS,… → Identify the network model — service… → …
  • The user mentions container security
  • SKILL.md covers Scope the Audit, Audit Checklist — Dockerfile, Audit Checklist — Kubernetes… and Audit Checklist — runtime, plus 3 more sections
  • Calls trivy, kubectl and git

What it does

Container Audit is an agent skill from briiirussell/cybersecurity-skills. Audit container images, Dockerfiles, and Kubernetes manifests for misconfigurations, excessive privileges, exposed secrets, and runtime risks. Use when the user mentions 'container security,' 'Docker security,' 'Dockerfile audit,' 'Kubernetes security,' 'K8s security,' 'pod security,' 'container hardening,' 'kubectl audit,' 'image scanning,' 'distroless,' 'rootless containers,' 'pod security policy,' 'pod security standards,' 'PSS,' 'network policy,' 'OPA Gatekeeper,' 'Kyverno,' 'runtime security,' or needs to…

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Containers, Container orchestration and Cloud security. It works with Kubernetes and Docker. The repository describes itself as: Cybersecurity skills for AI coding agents (Claude Code, Cursor, Codex). The licence is MIT.

When your agent uses it

  • The user mentions container security
  • Docker security
  • Dockerfile audit
  • Kubernetes security

Example prompts

  • “container security,”
  • “Docker security,”
  • “Dockerfile audit,”
  • “/container-audit”

Requirements

  • Docker
  • Pre-approved tools (allowed-tools): Bash, Read, Write, Grep, Glob, WebSearch

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Inventory the surface — Dockerfiles, base images, registries, Helm charts, K8s manifests, Kustomize overlays, CI build pipelines that…
  2. Identify the runtime — vanilla K8s, EKS, GKE, AKS, OpenShift, ECS Fargate, Cloud Run, Fly.io
  3. Identify the network model — service mesh, ingress controller, default-deny vs default-allow
  4. Identify the secret model — K8s Secrets (base64-only), External Secrets Operator, sealed-secrets, Vault, Doppler

What it can do on your machine

Read from SKILL.md and the folder at commit c9ade03. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read
    • Write
    • Grep
    • Glob
    • WebSearch

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • trivy
    • kubectl
    • git
    • apt-get
    • docker

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use kubectl, git and docker, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Container Audit loads about 2.5k tokens when it runs. Until then it costs about 144 tokens; SKILL.md has 876 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~144
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:31
    `.dockerignore` should exclude `.git`, `.env`, `node_modules`, `*.pem`, `.aws/`, `.ssh/`
  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read, Write, Grep, Glob, WebSearch

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from briiirussell/cybersecurity-skills at commit c9ade03, republished under its MIT licence (© briiirussell). 876 words, ~2,504 tokens.

Download SKILL.mdSave it as .claude/skills/container-audit/SKILL.md (or your agent's skills folder).
name
container-audit
description
Audit container images, Dockerfiles, and Kubernetes manifests for misconfigurations, excessive privileges, exposed secrets, and runtime risks. Use when the user mentions 'container security,' 'Docker security,' 'Dockerfile audit,' 'Kubernetes security,' 'K8s security,' 'pod security,' 'container hardening,' 'kubectl audit,' 'image scanning,' 'distroless,' 'rootless containers,' 'pod security policy,' 'pod security standards,' 'PSS,' 'network policy,' 'OPA Gatekeeper,' 'Kyverno,' 'runtime security,' or needs to review container or orchestration security.
allowed-tools
Bash, Read, Write, Grep, Glob, WebSearch

Container Audit — Docker & Kubernetes Security Review

Audit container images, Dockerfiles, Helm charts, Kustomize overlays, and Kubernetes manifests for misconfiguration, excessive privilege, exposed secrets, and runtime security gaps. Distinct from cloud-audit (cloud-provider IAM and managed services) and dependency-audit (package CVEs in the application). This skill is the container/orchestration layer between them.

Scope the Audit

  1. Inventory the surface — Dockerfiles, base images, registries, Helm charts, K8s manifests, Kustomize overlays, CI build pipelines that produce images
  2. Identify the runtime — vanilla K8s, EKS, GKE, AKS, OpenShift, ECS Fargate, Cloud Run, Fly.io
  3. Identify the network model — service mesh, ingress controller, default-deny vs default-allow
  4. Identify the secret model — K8s Secrets (base64-only), External Secrets Operator, sealed-secrets, Vault, Doppler

Audit Checklist — Dockerfile

Base image & supply chain
  • Pinned by digest, not tag — FROM node:20@sha256:abc... not FROM node:20 (which can move)
  • Distroless / minimal where possible — gcr.io/distroless/nodejs20, alpine (be aware of musl quirks), chainguard/*
  • Not using :latest — non-reproducible builds
  • Multi-stage builds discard build-time tooling — FROM build AS builder → FROM runtime final stage
  • Grep for: FROM .*:latest, FROM .*:[0-9]+$ (tag without digest)
Build-time exposure
  • Secrets passed via --build-arg end up in image layers visible to anyone who pulls the image — use BuildKit secrets (--mount=type=secret) or runtime env vars instead
  • COPY . . ships everything in the build context — .dockerignore should exclude .git, .env, node_modules, *.pem, .aws/, .ssh/
  • ADD <url> follows redirects and disables checksum verification — prefer RUN curl ... && sha256sum -c
  • Grep for: ARG .*KEY, ARG .*TOKEN, ARG .*SECRET, ENV .*=.*[A-Za-z0-9]{32,}, ADD http
Runtime posture
  • Non-root user — USER 1001 (or any non-zero UID) before CMD
  • No chmod 4755 SUID binaries in the final image
  • No unnecessary shells / package managers in the final stage — distroless / FROM scratch is the strong default
  • HEALTHCHECK defined so orchestrator can detect unhealthy containers
  • Read-only root filesystem at runtime (set via K8s; verify nothing in the image writes outside /tmp or a declared volume)
  • Grep for: USER root (or absence of any USER directive), chmod 4755, apt-get install.*sudo

Audit Checklist — Kubernetes manifests

Pod security
  • securityContext.runAsNonRoot: true and runAsUser set to a non-zero UID
  • securityContext.allowPrivilegeEscalation: false
  • securityContext.readOnlyRootFilesystem: true with explicit emptyDir mounts where the app needs to write
  • securityContext.capabilities.drop: ["ALL"] then add only what's needed
  • securityContext.privileged is never true in app workloads (Falco, kube-proxy, some CSI drivers are the rare legit exceptions)
  • hostNetwork, hostPID, hostIPC all false — yes on these is "container can see / talk to the node"
  • hostPath volumes — every one is a node-escape risk; review case by case
  • Grep for: privileged: true, runAsUser: 0, hostNetwork: true, hostPath:
Pod Security Standards (PSS) / admission
  • Cluster enforces restricted profile via PSS admission, or equivalent via OPA Gatekeeper / Kyverno
  • Pod Security Policies (deprecated since 1.21, removed in 1.25) are NOT what's enforcing this — confirm a current admission controller
  • No workloads in the kube-system namespace running app code
Network
  • NetworkPolicy exists for every namespace running app workloads — default-deny ingress AND egress, then allow specific pods
  • Missing NetworkPolicy = every pod can talk to every other pod on every port, including kube-apiserver and metadata service
  • Service mesh (Istio, Linkerd) mTLS in STRICT mode for sensitive namespaces, not PERMISSIVE
  • Ingress controllers terminate TLS properly; backend tls.crt / tls.key in K8s Secrets rotate
Show full SKILL.md (360 more words)Show less
Secrets
  • K8s Secrets are base64-encoded, NOT encrypted — by default they're plain bytes in etcd
  • etcd encryption at rest enabled — --encryption-provider-config on kube-apiserver
  • Workloads consume secrets via projected volumes, not environment variables (env vars leak via /proc/<pid>/environ, error reports, crash dumps)
  • External Secrets Operator / Vault / sealed-secrets bridge so the Git repo never contains plaintext
  • Grep for: kind: Secret in Git with data: fields (base64-encoded values committed)
RBAC
  • No ClusterRole with * verbs on * resources except cluster-admin (audit who's bound to it)
  • ServiceAccount per workload, not shared "default" SA
  • automountServiceAccountToken: false on workloads that don't need API access
  • Bindings of system:authenticated group are visible to every legitimate workload — almost always wrong
  • Grep for: verbs: ["*"], resources: ["*"], apiGroups: ["*"], system:authenticated
Resource limits
  • Every container has resources.requests and resources.limits set — missing limits = noisy neighbor + DoS surface (one pod can starve the node)
  • LimitRange per namespace as a backstop
  • ResourceQuota per namespace prevents tenant-vs-tenant resource exhaustion
Image policy
  • imagePullPolicy: Always for :latest (you shouldn't use :latest, but if you do) — otherwise the node caches stale images
  • Cluster-level policy that all images come from approved registries (your own + a small allow-list); enforced via Gatekeeper / Kyverno / image-policy-webhook
  • Image signature verification — cosign + sigstore policy controller, or Notary v2

Audit Checklist — runtime

  • Image scanning in CI — trivy image, grype, docker scout cves. Must run on every build; advisories should not block but should surface
  • Runtime detection — Falco / Tracee / Tetragon catches "shell spawned in a pod that has never opened a shell" patterns
  • Audit logs enabled — kube-apiserver audit log captures exec, attach, port-forward events for incident response
  • kubectl exec access tracked — not free for any cluster-admin to silently shell into prod

Useful one-liners

bash
# All Dockerfiles in the repo + their first FROM line
git ls-files | grep -E '(^|/)Dockerfile(\.|$)' | xargs -I{} sh -c 'echo "==> {}"; grep ^FROM "{}"'

# Manifests missing securityContext
grep -rL "securityContext" --include="*.yaml" --include="*.yml" .

# Manifests with privileged containers
grep -rln "privileged: *true" --include="*.yaml" --include="*.yml" .

# Manifests with hostPath volumes
grep -rln "hostPath:" --include="*.yaml" --include="*.yml" .

# Secrets in Git (base64-encoded but readable)
grep -rln "kind: *Secret" --include="*.yaml" --include="*.yml" . | xargs grep -l "^data:"

# Image scan (Trivy)
trivy image --severity HIGH,CRITICAL --exit-code 0 <image>

# Manifest scan (Trivy)
trivy config --severity HIGH,CRITICAL .

# Cluster posture (kube-bench, run inside the cluster)
kube-bench run --targets master,node,policies

Verify Fixes at Runtime

  • runAsNonRoot: true — verify the pod restarts cleanly and stays Running; if the image's ENTRYPOINT calls chown it'll crashloop
  • NetworkPolicy default-deny — verify legitimate traffic still works (run an in-cluster kubectl run -it --rm debug ... curl); silent partial outages are common after default-deny rollout
  • readOnlyRootFilesystem: true — verify the app doesn't write outside declared emptyDir mounts; log writes, PID files, and tmp files are common breakers
  • Image-policy enforcement — try to deploy an unsigned / off-list image; verify admission rejects it

Report Format

markdown
# Container Security Audit
## Target: [cluster name / image registry / repo path]
## Date: [date]

### Summary
- Dockerfiles audited: N
- Manifests audited: N
- Cluster posture checks: pass / fail counts

### Findings
| ID | Severity | Category | Location | Issue |
|----|----------|----------|----------|-------|

### Per-finding detail
#### [SEVERITY] [Title]
**File:** `path/to/manifest.yaml:42`
**Category:** Dockerfile | Pod security | RBAC | NetworkPolicy | Secrets | Resource limits | Image policy | Runtime

**Description:** [what the issue is]

**Vulnerable config:**
```yaml
[snippet]

Remediation:

yaml
[fixed snippet]

Verification: [observed behavior proving the fix holds]


Disposition rule (Fixed / Deferred / Accepted Risk) matches `owasp-audit`.

## Boundaries

- Only audit clusters and registries the user provides or has authorization for
- Never `kubectl delete` or modify cluster state during an audit — read-only operations only (`get`, `describe`, `auth can-i`)
- For runtime evidence, prefer non-disruptive checks (a `kubectl run -it --rm` ephemeral debug pod) over modifying running workloads
- Refuse cluster-takeover scenarios — escalating from a found weakness to a full pivot is exploitation, not audit
- Flag low-confidence findings as "Potential" rather than confirmed

## References

- CIS Docker Benchmark
- CIS Kubernetes Benchmark
- NSA/CISA Kubernetes Hardening Guide
- Pod Security Standards (PSS) — restricted, baseline, privileged
- OWASP Docker Security Cheat Sheet
- OWASP Kubernetes Security Cheat Sheet
- MITRE ATT&CK for Containers

© briiirussell, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/container-audit of briiirussell/cybersecurity-skills.

Open the folder on GitHubat commit c9ade03

Compare with similar skills

Container Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Container Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Container Audit this skillbriiirussell/cybersecurity-skills413—~2.5kAutomated safety check: NotesMIT
Performing Container Security Scanning With Trivymukul975/Anthropic-Cybersecurity-Skills34k—~818Automated safety check: PassApache-2.0
Config Scanjwynia/agent-skills170—~2kAutomated safety check: NotesMIT
Agent Bom Scan InfraLeoYeAI/openclaw-master-skills2.2k—~1.5kAutomated safety check: PassApache-2.0
Cloud AuditCommonHuman-Lab/nyxstrike157—~1.1kAutomated safety check: PassCustom licence
Container Securityhardw00t/ai-security-arsenal105—~2.8kAutomated safety check: PassNone

Similar skills

  • Performing Container Security Scanning With Trivy

    mukul975/Anthropic-Cybersecurity-Skills

    Runs Trivy across every target type it supports - container images, filesystems, Git repositories, and Kubernetes clusters - for OS and dependency vulnerabilities, IaC misconfiguration, exposed…

    34k GitHub stars~818 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Config Scan

    jwynia/agent-skills

    Detect security misconfigurations in config files, Docker, and IaC.

    170 GitHub stars~2k tokensUpdated 7 mo ago
    DevOps & CloudAuto-check: notes
  • Agent Bom Scan Infra

    LeoYeAI/openclaw-master-skills

    Scan infrastructure-as-code, cloud configurations, and find secrets.

    2.2k GitHub stars~1.5k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Cloud Audit

    CommonHuman-Lab/nyxstrike

    Cloud and container security auditing workflow using prowler, trivy, kube-hunter, and docker-bench for AWS, GCP, Azure, Kubernetes, and container images

    157 GitHub stars~1.1k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Container Security

    hardw00t/ai-security-arsenal

    Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and…

    105 GitHub stars~2.8k tokensUpdated 5 mo ago
    SecurityAuto-check passed
  • Container Security Hardening

    sickn33/agentic-awesome-skills

    Harden Docker/container images and runtime deployments with secure base images, non-root users, CVE scanning, SBOM/signing, seccomp/AppArmor, and Kubernetes pod security controls.

    47k GitHub starsUsed in 1 repo~1k tokens
    SecurityAuto-check: notes

More from briiirussell/cybersecurity-skills

All 25 skills in this repo
  • AI Risk Management

    briiirussell/cybersecurity-skills

    Apply the NIST AI Risk Management Framework (AI RMF 1.0) and adjacent guidance to AI / ML systems — model lifecycle governance, fairness and bias evaluation, robustness, transparency…

    413 GitHub stars~3.7k tokensUpdated 4 mo ago
    Auto-check: notes
  • API Audit

    briiirussell/cybersecurity-skills

    Audit REST, GraphQL, and RPC APIs against the OWASP API Security Top 10 (2023).

    413 GitHub stars~2.8k tokensUpdated 4 mo ago
    Auto-check: notes
  • Breach Patterns

    briiirussell/cybersecurity-skills

    Learn from public breach disclosures — extract the audit question each one implies and check your own stack.

    413 GitHub stars~3.5k tokensUpdated 4 mo ago
    Auto-check: notes
  • Cloud Audit

    briiirussell/cybersecurity-skills

    Audit cloud infrastructure (AWS, GCP, Azure) for misconfigurations, excessive permissions, and security gaps.

    413 GitHub stars~1.3k tokensUpdated 4 mo ago
    Auto-check: notes
  • Crypto Audit

    briiirussell/cybersecurity-skills

    Audit cryptography implementation — algorithm choice, key sizes, KDF parameters, IV/nonce handling, signature verification, randomness, TLS configuration, and key rotation.

    413 GitHub stars~2.8k tokensUpdated 4 mo ago
    Auto-check: notes
  • Csf Mapping

    briiirussell/cybersecurity-skills

    Map your security posture against the NIST Cybersecurity Framework 2.0 (Govern, Identify, Protect, Detect, Respond, Recover).

    413 GitHub stars~3k tokensUpdated 4 mo ago
    Auto-check: notes

Categories

Questions about Container Audit

What does Container Audit do?

Audit container images, Dockerfiles, and Kubernetes manifests for misconfigurations, excessive privileges, exposed secrets, and runtime risks. Container Audit is an agent skill from briiirussell/cybersecurity-skills. Audit container images, Dockerfiles, and Kubernetes manifests for misconfigurations, excessive privileges, exposed secrets, and runtime risks.

When should I use Container Audit?

Container Audit fits situations like: the user mentions container security; Docker security; dockerfile audit; Kubernetes security.

How do I install Container Audit in Claude Code?

Run `npx skills add briiirussell/cybersecurity-skills --skill container-audit -a claude-code`. Or copy the skill folder (skills/container-audit in briiirussell/cybersecurity-skills) into .claude/skills/container-audit in your project. Claude Code loads it when a task matches its description.

How do I install Container Audit in Codex?

Run `npx skills add briiirussell/cybersecurity-skills --skill container-audit -a codex`. Or copy the skill folder (skills/container-audit in briiirussell/cybersecurity-skills) into .agents/skills/container-audit in your project. Codex loads it when a task matches its description.

Can I use Container Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add briiirussell/cybersecurity-skills --skill container-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/container-audit, .gemini/skills/container-audit, .github/skills/container-audit and .opencode/skills/container-audit in your project.

What does Container Audit need to run?

Going by SKILL.md and its folder, Container Audit needs the command-line tools its instructions call (trivy, kubectl, git, apt-get and docker). Our summary lists: Docker. Its frontmatter pre-approves these tools: Bash, Read, Write, Grep, Glob, WebSearch.

Does Container Audit access the network?

SKILL.md contains no URLs. Its commands use git and docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Container Audit safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file; pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Container Audit use?

Container Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Container Audit use?

About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Container Audit?

Skills that share tags, products or a category with Container Audit: Performing Container Security Scanning With Trivy (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Config Scan (jwynia/agent-skills, 170 stars), Agent Bom Scan Infra (LeoYeAI/openclaw-master-skills, 2.2k stars) and Cloud Audit (CommonHuman-Lab/nyxstrike, 157 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Container Audit?

briiirussell (a GitHub user) maintains it in briiirussell/cybersecurity-skills, which has 413 GitHub stars. The repository holds 25 skills in this directory. The repository was last updated on May 27, 2026.

Source: briiirussell/cybersecurity-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.