Container Security is an agent skill from hardw00t/ai-security-arsenal. Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and runtime monitoring (Falco/Tetragon). Use when scanning Docker/OCI images, auditing K8s clusters, reviewing Dockerfiles, diffing SBOMs across releases, analyzing RBAC, or assessing container runtime posture. Triggers on requests involving Trivy, Grype, Syft, Kubescape, kube-bench, Falco, container escapes, or CIS…
Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 21 other files, including reference files (for example `examples/falco_custom_rule.yaml`, `examples/vulnerable_dockerfile.md` and `payloads/container_escape_poc.md`).
It sits in Security, covering Cloud security, Containers and Supply chain security. It works with Kubernetes, Docker and Trivy. The repository describes itself as: A collection of skills, agents, commands, and workflows for security researchers. Compatible with Claude Code, Claude Desktop, OpenCode, and other AI coding tools.