Agent skill

Kubernetes Security Auditor

by criptogus in criptogus/agent-evolve-network

Reviews Kubernetes manifests and cluster config for security misconfigurations, ranks them by blast radius, and gives a minimal hardening patch for each.

Apache-2.0Auto-check passedSecurity

Install Kubernetes Security Auditor

skills CLI
$ npx skills add criptogus/agent-evolve-network --skill kubernetes-security-auditor -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install criptogus/agent-evolve-network kubernetes-security-auditor --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/criptogus/agent-evolve-network.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/kubernetes-security-auditor .claude/skills/kubernetes-security-auditor && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
kubernetes-security-auditor
GitHub stars
288
Token cost
~1.3k tokens
SKILL.md length
333 words
Files
1
Skills in repo
107
Repo updated
First seen
Licence
Apache-2.0

At a glance

Reviews Kubernetes manifests and cluster config for security misconfigurations, ranks them by blast radius, and gives a minimal hardening patch for each.

  • The user asks for kubernetes security auditor work
  • SKILL.md covers Instructions, Always, Never and Input / output contract, plus 3 more sections
  • Reaches superagentskill.com
  • Mentions kubernetes

What it does

Kubernetes Security Auditor is an agent skill from criptogus/agent-evolve-network. Reviews Kubernetes manifests and cluster config for security misconfigurations, ranks them by blast radius, and gives a minimal hardening patch for each. Use when the user asks for kubernetes security auditor work, or mentions kubernetes, security, auditor.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Cloud security and Container orchestration. It works with Kubernetes. The licence is Apache-2.0.

When your agent uses it

  • The user asks for kubernetes security auditor work
  • Mentions kubernetes

Example prompts

  • “Use the kubernetes-security-auditor skill to review Kubernetes manifests and cluster config for security misconfigurations, ranks them by blast…”
  • “/kubernetes-security-auditor”

Requirements

  • Node.js

What it can do on your machine

Read from SKILL.md and the folder at commit d19b920. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are json and yaml).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • superagentskill.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Kubernetes Security Auditor loads about 1.3k tokens when it runs. Until then it costs about 71 tokens; SKILL.md has 333 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~71
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from criptogus/agent-evolve-network at commit d19b920, republished under its Apache-2.0 licence (© criptogus). 333 words, ~1,274 tokens.

Download SKILL.mdSave it as .claude/skills/kubernetes-security-auditor/SKILL.md (or your agent's skills folder).
name
kubernetes-security-auditor
description
Reviews Kubernetes manifests and cluster config for security misconfigurations, ranks them by blast radius, and gives a minimal hardening patch for each. Use when the user asks for kubernetes security auditor work, or mentions kubernetes, security, auditor.
version
0.1.0
license
Apache-2.0
homepage
https://superagentskill.com/marketplace/kubernetes-security-auditor
source
Super Agent Skill (SAK)

Kubernetes Security Auditor

Use when you have Kubernetes YAML (Deployments, Pods, RBAC, NetworkPolicies, PodSecurity) or a config dump and want a prioritized security review: privileged containers, hostPath/hostNetwork, missing resource limits, over-broad RBAC, absent NetworkPolicies, and image/pull-policy risks. Produces findings mapped to CIS Kubernetes Benchmark / MITRE ATT&CK for Containers, ranked by blast radius, each with a minimal patch. Does NOT apply changes, reach a live cluster, or run kubectl.

Adapted for Super Agent Skill from the open Anthropic-Cybersecurity-Skills corpus (Apache-2.0); restructured into a typed input -> output contract and hardened for adversarial review.

Instructions

You are a Kubernetes security auditor doing a static review of supplied manifests/config. For each finding output: severity (Critical/High/Medium/Low), the resource kind + name + field path, a one-line risk, the relevant CIS/ATT&CK reference, and a minimal patch (the smallest manifest change that fixes the root cause). Rank by blast radius: cluster-wide RBAC and node-level escapes outrank a single pod. Only flag fields present in the provided manifests. End with a "Not assessed" list of controls you could not evaluate from the given input.

Always

  • Rank findings by blast radius (cluster-wide before single-pod).
  • Cite the resource kind, name and field path for every finding.
  • Provide a minimal patch that fixes the root cause, not a symptom.
  • Map each finding to a CIS Kubernetes Benchmark or ATT&CK-for-Containers reference.

Never

  • Flag fields that are not present in the supplied manifests.
  • Recommend disabling security controls to resolve an error.
  • Output destructive kubectl commands.

Input / output contract

Input:

json
{
  "type": "object",
  "properties": {
    "manifests": {
      "type": "array",
      "items": {
        "type": "object"
      }
    },
    "cluster_context": {
      "type": "string"
    }
  },
  "required": [
    "manifests"
  ]
}

Output:

json
{
  "type": "object",
  "properties": {
    "findings": {
      "type": "array",
      "items": {
        "type": "object"
      }
    },
    "not_assessed": {
      "type": "array",
      "items": {
        "type": "string"
      }
    }
  },
  "required": [
    "findings"
  ]
}

Examples

Privileged container with hostPath

Input:

manifests:
  - kind: Pod
    metadata: { name: log-shipper }
    spec:
      containers:
        - name: shipper
          image: shipper:latest
          securityContext: { privileged: true }
          volumeMounts: [{ name: host, mountPath: /host }]
      volumes: [{ name: host, hostPath: { path: / } }]

Expected output:

## Critical
- **Pod/log-shipper — spec.containers[0].securityContext.privileged** — Privileged
  container with hostPath `/` mounted = trivial node takeover / container escape.
  CIS 5.2.1; ATT&CK T1611 (Escape to Host).
  Patch:
  ```yaml
  securityContext:
    privileged: false
    allowPrivilegeEscalation: false
    readOnlyRootFilesystem: true
    capabilities: { drop: ["ALL"] }
  # remove the hostPath '/' mount; scope to the exact path needed, read-only

Medium

  • Pod/log-shipper — image: shipper:latest — :latest tag is non-deterministic. Pin to a digest. CIS 5.1.x. Not assessed: RBAC, NetworkPolicy (none supplied).

### Over-broad RBAC

Input:

manifests:

  • kind: ClusterRoleBinding metadata: { name: ci-admin } roleRef: { kind: ClusterRole, name: cluster-admin } subjects: [{ kind: ServiceAccount, name: ci, namespace: build }]

Expected output:

Critical

  • ClusterRoleBinding/ci-admin — roleRef cluster-admin — Binds the ci ServiceAccount to cluster-admin cluster-wide; a compromised CI token owns the cluster. CIS 5.1.1; ATT&CK T1078 (Valid Accounts). Patch: replace with a namespaced Role granting only the verbs/resources CI needs, bound via a RoleBinding in build:
    yaml
    kind: RoleBinding
    roleRef: { kind: Role, name: ci-deployer }

## Trust & telemetry

This skill is graded on the Super Agent Skill network: format, substance and adversarial
(prompt-injection) testing produce a public Trust Score.

- Trust Score & evidence: https://superagentskill.com/marketplace/trust/kubernetes-security-auditor
- Skill page: https://superagentskill.com/marketplace/kubernetes-security-auditor
- Live version (always current) via MCP: https://superagentskill.com/api/mcp

Reinstall or update with `npx skills update`, or pull the live graded version with
`npx super-agent install kubernetes-security-auditor`.

© criptogus, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/kubernetes-security-auditor of criptogus/agent-evolve-network.

Open the folder on GitHubat commit d19b920

Compare with similar skills

Kubernetes Security Auditor next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Kubernetes Security Auditor compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Kubernetes Security Auditor this skillcriptogus/agent-evolve-network288—~1.3kAutomated safety check: PassApache-2.0
Container Securityhardw00t/ai-security-arsenal104—~2.8kAutomated safety check: PassNone
Container Security Hardeningsickn33/agentic-awesome-skills47k1 repos~1kAutomated safety check: NotesMIT
KubeShark for KubernetesLukasNiessen/kubernetes-skill444—~1.2kAutomated safety check: PassMIT
Performing Container Security Scanning With Trivymukul975/Anthropic-Cybersecurity-Skills34k—~818Automated safety check: PassApache-2.0
Security Analyzeraiskillstore/marketplace430—~1.2kAutomated safety check: NotesNone

Similar skills

  • Container Security

    hardw00t/ai-security-arsenal

    Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and…

    104 GitHub stars~2.8k tokensUpdated 5 mo ago
    SecurityAuto-check passed
  • Container Security Hardening

    sickn33/agentic-awesome-skills

    Harden Docker/container images and runtime deployments with secure base images, non-root users, CVE scanning, SBOM/signing, seccomp/AppArmor, and Kubernetes pod security controls.

    47k GitHub starsUsed in 1 repo~1k tokens
    SecurityAuto-check: notes
  • KubeShark for Kubernetes

    LukasNiessen/kubernetes-skill

    Keeps Kubernetes manifests, Helm charts and policies grounded by diagnosing six failure modes, such as insecure defaults and API drift, and loading only matching references.

    444 GitHub stars~1.2k tokensUpdated 25 days ago
    DevOps & CloudAuto-check passed
  • Performing Container Security Scanning With Trivy

    mukul975/Anthropic-Cybersecurity-Skills

    Runs Trivy across every target type it supports - container images, filesystems, Git repositories, and Kubernetes clusters - for OS and dependency vulnerabilities, IaC misconfiguration, exposed…

    34k GitHub stars~818 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Security Analyzer

    aiskillstore/marketplace

    Comprehensive security vulnerability analysis for codebases and infrastructure.

    430 GitHub stars~1.2k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Operate kubectl, kube-bench, Trivy, Prowler, and manifest/runtime evidence for advanced Kubernetes security assessment.

    135 GitHub stars~898 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed

More from criptogus/agent-evolve-network

All 107 skills in this repo
  • Brand Research

    criptogus/agent-evolve-network

    Kickoff research for a brand you haven't worked on before — web research, existing-ad analysis from the Meta Ad Library, editorial-grammar profiling, sourced + AI-generated brand assets, hook/CTA…

    288 GitHub stars~3.9k tokensUpdated 28 days ago
    Auto-check passed
  • Create Apple Notes Video Ad

    criptogus/agent-evolve-network

    Produce a 9:16 social-native ad recreating the iPhone Apple Notes typing experience — the note begins with 1–2 visible lines, then progressively types additional paragraphs character-by-character…

    288 GitHub stars~4.9k tokensUpdated 28 days ago
    Auto-check passed
  • Create Chatgpt Video Ad

    criptogus/agent-evolve-network

    Produce a 9:16 social-native ad that recreates a ChatGPT mobile chat — user types in the composer with the iOS keyboard visible, taps send, keyboard slides down, header right-cluster swaps…

    288 GitHub stars~5k tokensUpdated 28 days ago
    Auto-check passed
  • Create Imessage Video Ad

    criptogus/agent-evolve-network

    Produce a 9:16 social-native ad that recreates an iMessage conversation reveal — bubbles pop in over time, composer types char-by-char, real Apple iMessage SFX hit on every send/receive, music bed…

    288 GitHub stars~7.4k tokensUpdated 28 days ago
    Auto-check passed
  • Cloud Misconfig Auditor

    criptogus/agent-evolve-network

    Audits AWS, GCP and Azure environments (and matching IaC) for excessive permissions, public exposure, weak encryption defaults and missing logging.

    288 GitHub stars~965 tokensUpdated 28 days ago
    Auto-check passed
  • Cloudflare Workers Expert

    criptogus/agent-evolve-network

    Builds and debugs Cloudflare Workers, Durable Objects, KV, R2, D1, and Queues with edge-correct patterns.

    288 GitHub stars~619 tokensUpdated 28 days ago
    Auto-check passed

Works with

Questions about Kubernetes Security Auditor

What does Kubernetes Security Auditor do?

Reviews Kubernetes manifests and cluster config for security misconfigurations, ranks them by blast radius, and gives a minimal hardening patch for each. Kubernetes Security Auditor is an agent skill from criptogus/agent-evolve-network. Reviews Kubernetes manifests and cluster config for security misconfigurations, ranks them by blast radius, and gives a minimal hardening patch for each.

When should I use Kubernetes Security Auditor?

Kubernetes Security Auditor fits situations like: the user asks for kubernetes security auditor work; mentions kubernetes.

How do I install Kubernetes Security Auditor in Claude Code?

Run `npx skills add criptogus/agent-evolve-network --skill kubernetes-security-auditor -a claude-code`. Or copy the skill folder (skills/kubernetes-security-auditor in criptogus/agent-evolve-network) into .claude/skills/kubernetes-security-auditor in your project. Claude Code loads it when a task matches its description.

How do I install Kubernetes Security Auditor in Codex?

Run `npx skills add criptogus/agent-evolve-network --skill kubernetes-security-auditor -a codex`. Or copy the skill folder (skills/kubernetes-security-auditor in criptogus/agent-evolve-network) into .agents/skills/kubernetes-security-auditor in your project. Codex loads it when a task matches its description.

Can I use Kubernetes Security Auditor in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add criptogus/agent-evolve-network --skill kubernetes-security-auditor -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/kubernetes-security-auditor, .gemini/skills/kubernetes-security-auditor, .github/skills/kubernetes-security-auditor and .opencode/skills/kubernetes-security-auditor in your project.

What does Kubernetes Security Auditor need to run?

SKILL.md names no scripts, command-line tools or credentials: Kubernetes Security Auditor is instructions for the agent only. Our summary lists: Node.js.

Does Kubernetes Security Auditor access the network?

SKILL.md names 1 domain. In commands or code: superagentskill.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Kubernetes Security Auditor safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Kubernetes Security Auditor use?

Kubernetes Security Auditor is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Kubernetes Security Auditor use?

About 1.3k tokens (SKILL.md is roughly 5.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Kubernetes Security Auditor?

Skills that share tags, products or a category with Kubernetes Security Auditor: Container Security (hardw00t/ai-security-arsenal, 104 stars), Container Security Hardening (sickn33/agentic-awesome-skills, 47k stars), KubeShark for Kubernetes (LukasNiessen/kubernetes-skill, 444 stars) and Performing Container Security Scanning With Trivy (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Kubernetes Security Auditor?

criptogus (a GitHub user) maintains it in criptogus/agent-evolve-network, which has 288 GitHub stars. The repository holds 107 skills in this directory. The repository was last updated on September 9, 2026.

Source: criptogus/agent-evolve-network on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.