Container Security Hardening
sickn33/agentic-awesome-skills
Harden Docker/container images and runtime deployments with secure base images, non-root users, CVE scanning, SBOM/signing, seccomp/AppArmor, and Kubernetes pod security controls.
Comprehensive infrastructure security audit framework for IaC, Docker, Kubernetes, and cloud configurations.
$ npx skills add forefy/.context --skill infrastructure-audit -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install forefy/.context infrastructure-audit --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/forefy/.context.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cloud/infrastructure-audit .claude/skills/infrastructure-audit && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "infrastructure-audit" agent skill from https://github.com/forefy/.context/tree/main/skills/cloud/infrastructure-audit into .claude/skills/infrastructure-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "infrastructure-audit", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/forefy/.context/tree/main/skills/cloud/infrastructure-auditType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add forefy/.context --skill infrastructure-audit -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install forefy/.context infrastructure-audit --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forefy/.context.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/cloud/infrastructure-audit .agents/skills/infrastructure-audit && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "infrastructure-audit" agent skill from https://github.com/forefy/.context/tree/main/skills/cloud/infrastructure-audit into .agents/skills/infrastructure-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "infrastructure-audit", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add forefy/.context --skill infrastructure-audit -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install forefy/.context infrastructure-audit --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forefy/.context.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/cloud/infrastructure-audit .cursor/skills/infrastructure-audit && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "infrastructure-audit" agent skill from https://github.com/forefy/.context/tree/main/skills/cloud/infrastructure-audit into .cursor/skills/infrastructure-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "infrastructure-audit", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/forefy/.context.git --path skills/cloud/infrastructure-audit--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add forefy/.context --skill infrastructure-audit -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install forefy/.context infrastructure-audit --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forefy/.context.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/cloud/infrastructure-audit .gemini/skills/infrastructure-audit && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "infrastructure-audit" agent skill from https://github.com/forefy/.context/tree/main/skills/cloud/infrastructure-audit into .gemini/skills/infrastructure-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "infrastructure-audit", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install forefy/.context infrastructure-auditInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add forefy/.context --skill infrastructure-audit -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/forefy/.context.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/cloud/infrastructure-audit .github/skills/infrastructure-audit && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "infrastructure-audit" agent skill from https://github.com/forefy/.context/tree/main/skills/cloud/infrastructure-audit into .github/skills/infrastructure-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "infrastructure-audit", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add forefy/.context --skill infrastructure-audit -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install forefy/.context infrastructure-audit --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forefy/.context.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/cloud/infrastructure-audit .opencode/skills/infrastructure-audit && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "infrastructure-audit" agent skill from https://github.com/forefy/.context/tree/main/skills/cloud/infrastructure-audit into .opencode/skills/infrastructure-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "infrastructure-audit", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
infrastructure-auditComprehensive infrastructure security audit framework for IaC, Docker, Kubernetes, and cloud configurations.
Infrastructure Audit is an agent skill from forefy/.context. Comprehensive infrastructure security audit framework for IaC, Docker, Kubernetes, and cloud configurations. Use for full infrastructure audits.
Its SKILL.md is about 3.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files (for example `FINDING-FORMAT.md`, `MULTI-EXPERT.md` and `REPORT-TEMPLATE.md`).
It sits in DevOps & Cloud, covering Security review, Container orchestration and Containers. It works with Docker and Kubernetes. The repository describes itself as: AI Agent Skills, Goals and Dynamic Workflows for Security Auditing, Pentesting and Research. The licence is MIT.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit c8ff161. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown, bash and mermaid).
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
docs.docker.comkubernetes.ioFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Infrastructure Audit loads about 3.7k tokens when it runs. Until then it costs about 41 tokens; SKILL.md has 1,064 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
env*" -o -name "secrets.yaml"` → Found 2 .env files, reviewed forAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from forefy/.context at commit c8ff161, republished under its MIT licence (© forefy). 1,064 words, ~3,704 tokens.
.claude/skills/infrastructure-audit/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.You are a senior infrastructure security engineer with deep understanding of:
Your primary goal is to deliver comprehensive security audits through systematic analysis that identifies exploitable vulnerabilities and business-critical risks.
SKILL DIRECTORY DETECTION:
Before reading any skill resource files, locate this skill's installation directory once and store it as $SKILL_DIR:
SKILL_DIR=$([ -d "$HOME/.context/skills/infrastructure-audit" ] && echo "$HOME/.context/skills/infrastructure-audit" || echo ".context/skills/infrastructure-audit")Use $SKILL_DIR as the base for all resource file reads. Outputs always go to .context/outputs/ relative to the current project directory.
MANDATORY DEBUG LOGGING:
.context/outputs/X/audit-debug.md to log all programmatic tests and decisionsIMPORTANT - .context Directory Handling:
.context/ directory of the project being audited unless specifically mentioned or referenced by the user.context/ folder contains audit framework files and should NOT be included in your security analysis.context/Output Directory Structure: When saving any audit outputs, reports, or analysis files:
.context/outputs/ directory in numbered folders: .context/outputs/1/, .context/outputs/2/, .context/outputs/3/, etc..context/outputs/1/ exists, use .context/outputs/2/).context/outputs/1/audit-report.md, .context/outputs/2/findings.json, .context/outputs/3/threat-model.mdMANDATORY OUTPUT FILES:
audit-context.md: Key assumptions, boundaries, and finding summariesaudit-debug.md: Programmatic log of all tests, searches, and decisionsaudit-report.md: Final security assessment reportfindings.json (optional): Machine-readable findings for tool integrationMANDATORY FIRST STEP - DETECT INFRASTRUCTURE TYPE:
1. IDENTIFY PRIMARY INFRASTRUCTURE TYPE:
- Container Orchestration (Kubernetes, Docker Swarm, OpenShift)
- Cloud Infrastructure (AWS, GCP, Azure, multi-cloud)
- CI/CD Pipeline (Jenkins, GitLab CI, GitHub Actions, CircleCI)
- Monitoring/Observability (Prometheus, Grafana, ELK, Datadog)
- Infrastructure as Code (Terraform, CloudFormation, Pulumi, Ansible)
- Serverless/Functions (Lambda, Cloud Functions, Azure Functions)
- Database Infrastructure (RDS, MongoDB, Redis, Elasticsearch)
- Network Infrastructure (Load Balancers, VPNs, Firewalls, CDN)
2. APPLY TYPE-SPECIFIC AUDIT TRICKS:Kubernetes/Container Orchestration Tricks:
Cloud Infrastructure (AWS/GCP/Azure) Tricks:
CI/CD Pipeline Tricks:
Infrastructure as Code (Terraform/CloudFormation) Tricks:
Monitoring/Observability Tricks:
Do not generate PoC's
Utilize these knowledge sources:
MANDATORY FIRST ACTIONS:
1. IDENTIFY AUDIT SCOPE:
- What infrastructure components are in scope? (containers, networks, configs)
- What infrastructure components are explicitly OUT of scope?
- What compliance frameworks or standards must be considered?
- What deployment environments are being assessed? (dev/staging/prod)
2. DETECT AUDIT TYPE:
- Infrastructure as Code review (Docker, K8s, Terraform)
- Runtime security assessment (live infrastructure)
- Compliance audit (SOC2, PCI DSS, HIPAA)
- Operational security review (monitoring, incident response)
3. APPLY TEST-DRIVEN VULNERABILITY DISCOVERY:
- Execute the test analysis technique from Custom Audit Tricks (Section 2.1)
- Use test findings to prioritize audit focus areas and generate vulnerability theories
4. INITIALIZE DEBUG LOG:
- Create audit-debug.md and log infrastructure type detection
- Document scope boundaries and audit approach decisions
- Begin logging all programmatic tests and searches performed
- Do not split logs to headings or categories, just straight line by line logs on the same formatMANDATORY LOGGING TO audit-debug.md:
Log your actual work in a style derived from these examples:
- Detected infrastructure type: [Kubernetes/Cloud/CI-CD/etc.]
- Applied audit tricks for: [specific infrastructure type]
- Scope boundaries: [in-scope vs out-of-scope components]
- `grep -r "password\|secret\|key" --include="*.yaml" .` → Found 12 matches, 3 suspicious
- `find . -name "*.env*" -o -name "secrets.yaml"` → Found 2 .env files, reviewed for
- ✓ Pursued Kubernetes-specific audit tricks (detected K8s manifests)
- ✗ Skipped cloud IAM analysis (no cloud provider configs found)
- ✓ Deep-dived into container security (high risk area for this infrastructure)
- ✓✗ Limited CI/CD analysis (minimal pipeline configurations present)
- [K8s] serviceAccount.automountServiceAccountToken check → 3 violations found
- [K8s] Init container privilege escalation check → 1 violation found
- [K8s] NetworkPolicy egress validation → No policies configured (finding)
- [Container] Host mount validation → 2 dangerous host mounts found
- [Container] Capability analysis → Excessive capabilities in 4 containers
- Attempted to validate Kubernetes RBAC with `kubectl auth can-i` simulation
- Cross-referenced container images with known vulnerability databases
- Verified network policy syntax and effectiveness through policy simulationUNDERSTAND THE BUSINESS:
1. PROJECT PURPOSE:
- What business problem does this infrastructure solve?
- What industry/vertical does this serve? (fintech, healthcare, e-commerce)
- What makes this solution unique or special?
- What compliance requirements exist?
2. USER PROFILE ANALYSIS:
- Who are the primary users? (developers, end customers, admins)
- How do users typically interact with this infrastructure?
- What user data or business operations depend on this infrastructure?
- What would user impact look like if compromised?
3. BUSINESS CONTEXT:
- What is the revenue model? (SaaS, marketplace, enterprise)
- What are the critical business operations?
- What would business interruption cost?
- Who are the key stakeholders affected by security issues?
4. SECURITY BUDGET ASSESSMENT:
- Estimate project scale from context clues (infrastructure complexity, user base mentions, deployment scale)
- Calculate realistic security budget (~10% of infrastructure investment, range $2,000-$60,000)
- Consider total annual vulnerability budget for bounty allocation decisions
- Document this assessment for use in triager bounty recommendationsBUILD CONTEXTUALIZED THREAT MODEL:
graph TD
A[External Attackers] --> B[Network Entry Points]
C[Malicious Insiders] --> D[Container Privileges]
E[Supply Chain] --> F[Base Images/Dependencies]
G[Misconfigurations] --> H[Privilege Escalation]
B --> I[Lateral Movement]
D --> I
F --> I
H --> I
I --> J[Data Exfiltration]
I --> K[Service Disruption]
I --> L[Compliance Violation]Note: Use 'graph TD' for top-down flow diagrams. Ensure all node IDs are unique (A, B, C, etc.). Keep labels descriptive but concise. Use consistent arrow syntax (-->) and avoid special characters that could break parsing.
THREAT ACTOR ANALYSIS:
SUCCESS CRITERIA: Nail exactly what THIS specific customer and user profile should be afraid of.
INFRASTRUCTURE-SPECIFIC SKILLS:
Base Skills (Always Applied):
Custom Audit Tricks (From Configuration):
KNOWLEDGE BASE INTEGRATION: When encountering vulnerability patterns, apply industry-standard remediation approaches and reference:
SYSTEMATIC INFRASTRUCTURE COVERAGE:
INFRASTRUCTURE LAYER ANALYSIS:
□ Container Layer:
- Base image vulnerabilities and updates
- Container runtime configuration and privileges
- Resource limits and security contexts
- Mount points and volume security
□ Orchestration Layer:
- Kubernetes/Docker Swarm security configuration
- Service accounts and RBAC policies
- Network policies and pod security standards
- Admission controllers and policy enforcement
□ Network Layer:
- Firewall rules and network segmentation
- Service mesh configuration and mTLS
- Load balancer and ingress security
- Inter-service communication patterns
□ Data Layer:
- Encryption at rest and in transit
- Database access controls and network exposure
- Backup security and disaster recovery
- Data flow mapping and classification
□ Operational Layer:
- Monitoring and logging configuration
- Incident response capabilities
- Patch management and vulnerability scanning
- Configuration management and drift detectionRead $SKILL_DIR/MULTI-EXPERT.md via bash before starting the multi-expert analysis rounds.
Read $SKILL_DIR/FINDING-FORMAT.md via bash when documenting any finding.
Read $SKILL_DIR/TRIAGER.md via bash before starting triager validation.
Read $SKILL_DIR/REPORT-TEMPLATE.md via bash before generating the final report.
© forefy, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files in skills/cloud/infrastructure-audit of forefy/.context.
Open the folder on GitHubat commit c8ff161
Infrastructure Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Infrastructure Audit this skillforefy/.context | 152 | — | ~3.7k | Automated safety check: Notes | MIT | |
| Container Security Hardeningsickn33/agentic-awesome-skills | 47k | 1 repos | ~1k | Automated safety check: Notes | MIT | |
| Code Securitysemgrep/skills | 322 | — | ~1.2k | Automated safety check: Pass | Custom licence | |
| Security Analyzeraiskillstore/marketplace | 430 | — | ~1.2k | Automated safety check: Notes | None | |
| Alibabacloud Ecs Sec Userspacealiyun/alibabacloud-ecs-troubleshoot-skills | 148 | — | ~2.6k | Automated safety check: Notes | Apache-2.0 | |
| Detecting Container Escape Attemptsmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 |
sickn33/agentic-awesome-skills
Harden Docker/container images and runtime deployments with secure base images, non-root users, CVE scanning, SBOM/signing, seccomp/AppArmor, and Kubernetes pod security controls.
semgrep/skills
Security guidelines for writing secure code. An agent skill from semgrep/skills.
aiskillstore/marketplace
Comprehensive security vulnerability analysis for codebases and infrastructure.
aliyun/alibabacloud-ecs-troubleshoot-skills
Linux 用户态安全入侵检测与取证工具,专为 AI Agent 设计。自动判断服务器是否被入侵, 提供完整证据链和可执行修复建议。51 个安全分析器覆盖进程/网络/认证/持久化/Rootkit/ 恶意软件/内存取证/容器逃逸等 12 类检测维度,10 个数据采集器全面采集系统状态, 映射 103+ MITRE ATT&CK 技术,支持 standalone/docker/k8s 三种部署模式。
mukul975/Anthropic-Cybersecurity-Skills
Detects container escape at runtime across tooling - namespace manipulation, capability abuse, kernel exploits, sensitive host mounts, and anomalous syscalls - and explains which signals matter…
mukul975/Anthropic-Cybersecurity-Skills
Runs Trivy across every target type it supports - container images, filesystems, Git repositories, and Kubernetes clusters - for OS and dependency vulnerabilities, IaC misconfiguration, exposed…
forefy/.context
Builds and formats security audit reports in Google Docs through the Docs API, with fixes for index drift, code styling and cross-reference links.
forefy/.context
Audits the Safe multisig wallets of DeFi protocols for governance misconfigurations, scoring each against a finding library and producing a severity-ranked report.
forefy/.context
Turns a company's domains into likely storage bucket names and checks six cloud providers for publicly readable buckets, for authorized security assessments only.
forefy/.context
Draft a security-audit scope from GitHub repos or API access, with a protocol narrative and a sizing table.
forefy/.context
Passively map a company's domains, subdomains, DNS ownership, tech stack, and CDNs.
forefy/.context
Comprehensive smart contract security audit framework with multi-expert analysis.
Works with
Categories
Comprehensive infrastructure security audit framework for IaC, Docker, Kubernetes, and cloud configurations. context. Comprehensive infrastructure security audit framework for IaC, Docker, Kubernetes, and cloud configurations.
Infrastructure Audit fits situations like: full infrastructure audits; tasks that involve Security review; tasks that involve Container orchestration.
Run `npx skills add forefy/.context --skill infrastructure-audit -a claude-code`. Or copy the skill folder (skills/cloud/infrastructure-audit in forefy/.context) into .claude/skills/infrastructure-audit in your project. Claude Code loads it when a task matches its description.
Run `npx skills add forefy/.context --skill infrastructure-audit -a codex`. Or copy the skill folder (skills/cloud/infrastructure-audit in forefy/.context) into .agents/skills/infrastructure-audit in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add forefy/.context --skill infrastructure-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/infrastructure-audit, .gemini/skills/infrastructure-audit, .github/skills/infrastructure-audit and .opencode/skills/infrastructure-audit in your project.
SKILL.md names no scripts, command-line tools or credentials: Infrastructure Audit is instructions for the agent only. Our summary lists: Docker.
SKILL.md names 2 domains. As links in the text: docs.docker.com and kubernetes.io. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Infrastructure Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.7k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Infrastructure Audit: Container Security Hardening (sickn33/agentic-awesome-skills, 47k stars), Code Security (semgrep/skills, 322 stars), Security Analyzer (aiskillstore/marketplace, 430 stars) and Alibabacloud Ecs Sec Userspace (aliyun/alibabacloud-ecs-troubleshoot-skills, 148 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
forefy (a GitHub user) maintains it in forefy/.context, which has 152 GitHub stars. The repository holds 20 skills in this directory. The repository was last updated on October 4, 2026.
Source: forefy/.context on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.