Install the "k8s-security-policies" agent skill from https://github.com/Cybereason-Public/owLSM/tree/main/.cursor/skills/k8s-security-policies into .claude/skills/k8s-security-policies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "k8s-security-policies", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add Cybereason-Public/owLSM --skill k8s-security-policies -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "k8s-security-policies" agent skill from https://github.com/Cybereason-Public/owLSM/tree/main/.cursor/skills/k8s-security-policies into .agents/skills/k8s-security-policies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "k8s-security-policies", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add Cybereason-Public/owLSM --skill k8s-security-policies -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "k8s-security-policies" agent skill from https://github.com/Cybereason-Public/owLSM/tree/main/.cursor/skills/k8s-security-policies into .cursor/skills/k8s-security-policies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "k8s-security-policies", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add Cybereason-Public/owLSM --skill k8s-security-policies -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "k8s-security-policies" agent skill from https://github.com/Cybereason-Public/owLSM/tree/main/.cursor/skills/k8s-security-policies into .gemini/skills/k8s-security-policies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "k8s-security-policies", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add Cybereason-Public/owLSM --skill k8s-security-policies -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "k8s-security-policies" agent skill from https://github.com/Cybereason-Public/owLSM/tree/main/.cursor/skills/k8s-security-policies into .github/skills/k8s-security-policies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "k8s-security-policies", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add Cybereason-Public/owLSM --skill k8s-security-policies -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "k8s-security-policies" agent skill from https://github.com/Cybereason-Public/owLSM/tree/main/.cursor/skills/k8s-security-policies into .opencode/skills/k8s-security-policies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "k8s-security-policies", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Facts
Skill name
k8s-security-policies
GitHub stars
280
Used in
12 other repos
Token cost
~2k tokens
SKILL.md length
357 words
Files
3 (incl. references, assets)
Skills in repo
9
Repo updated
First seen
Licence
GPL-2.0
At a glance
Comprehensive guide for implementing NetworkPolicy, PodSecurityPolicy, RBAC, and Pod Security Standards in Kubernetes.
Works in 3 steps: Privileged (Unrestricted) → Baseline (Minimally restrictive) → Restricted (Most restrictive)
Tasks that involve Container orchestration
SKILL.md covers Do not use this skill when, Instructions, Purpose and Use this skill when, plus 9 more sections
Calls kubectl
What it does
K8s Security Policies is an agent skill from Cybereason-Public/owLSM. Comprehensive guide for implementing NetworkPolicy, PodSecurityPolicy, RBAC, and Pod Security Standards in Kubernetes.
Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files and assets (for example `assets/network-policy-template.yaml` and `references/rbac-patterns.md`).
It sits in Backend & APIs, covering Container orchestration and Authorization and RBAC. It works with Kubernetes and Linux. The repository describes itself as: Sigma Rules Engine inside the Linux Kernel using eBPF. Focusing on prevention capabilities. The licence is GPL-2.0.
When your agent uses it
Tasks that involve Container orchestration
Tasks that involve Authorization and RBAC
Example prompts
“/k8s-security-policies”
Workflow steps
3 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 8e541af. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Runs code
Shell commands in SKILL.md call:
kubectl
From the folder's file list and the shell code blocks in SKILL.md.
Network
No URLs in SKILL.md. Its commands use kubectl, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Context cost
K8s Security Policies loads about 2k tokens when it runs, and up to ~3k if it reads all its reference files. Until then it costs about 35 tokens; SKILL.md has 357 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~35
When it runs· the whole SKILL.md, loaded when a task matches
~2k
With references· SKILL.md plus every file in references/, read only if the agent opens them
~3k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check passed
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Download SKILL.mdSave it as .claude/skills/k8s-security-policies/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
k8s-security-policies
description
Comprehensive guide for implementing NetworkPolicy, PodSecurityPolicy, RBAC, and Pod Security Standards in Kubernetes.
risk
critical
source
community
date_added
2026-02-27
Kubernetes Security Policies
Comprehensive guide for implementing NetworkPolicy, PodSecurityPolicy, RBAC, and Pod Security Standards in Kubernetes.
Do not use this skill when
The task is unrelated to kubernetes security policies
You need a different domain or tool outside this scope
Instructions
Clarify goals, constraints, and required inputs.
Apply relevant best practices and validate outcomes.
Provide actionable steps and verification.
If detailed examples are required, open resources/implementation-playbook.md.
Purpose
Implement defense-in-depth security for Kubernetes clusters using network policies, pod security standards, and RBAC.
We found 27 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 12 other GitHub owners. This page covers the copy in Cybereason-Public/owLSM, which our catalogue first saw on October 7, 2026.
K8s Security Policies next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
K8s Security Policies compared with similar skills
Skill
Stars
Used in
Tokens
Auto-check
Licence
Repo updated
K8s Security Policies this skillCybereason-Public/owLSM
Detects and prevents privilege escalation inside Kubernetes pods by combining admission control (OPA policies), runtime monitoring (Falco), and audit log analysis of security contexts, Linux…
Hardens Kubernetes RBAC by designing least-privilege Roles and ClusterRoles, auditing RoleBindings, eliminating cluster-admin sprawl, separating service accounts, and integrating an external OIDC…
Finds over-permissive RBAC roles and service-account token abuse paths in a Kubernetes cluster using kubectl auth can-i, rbac-police, kubectl-who-can, and rakkess, tracing which subjects can…
Step-by-step guidance for creating production-ready Kubernetes manifests including Deployments, Services, ConfigMaps, Secrets, and PersistentVolumeClaims.
Comprehensive guide for implementing NetworkPolicy, PodSecurityPolicy, RBAC, and Pod Security Standards in Kubernetes. K8s Security Policies is an agent skill from Cybereason-Public/owLSM. Comprehensive guide for implementing NetworkPolicy, PodSecurityPolicy, RBAC, and Pod Security Standards in Kubernetes.
When should I use K8s Security Policies?
K8s Security Policies fits situations like: tasks that involve Container orchestration; tasks that involve Authorization and RBAC.
How do I install K8s Security Policies in Claude Code?
Run `npx skills add Cybereason-Public/owLSM --skill k8s-security-policies -a claude-code`. Or copy the skill folder (.cursor/skills/k8s-security-policies in Cybereason-Public/owLSM) into .claude/skills/k8s-security-policies in your project. Claude Code loads it when a task matches its description.
How do I install K8s Security Policies in Codex?
Run `npx skills add Cybereason-Public/owLSM --skill k8s-security-policies -a codex`. Or copy the skill folder (.cursor/skills/k8s-security-policies in Cybereason-Public/owLSM) into .agents/skills/k8s-security-policies in your project. Codex loads it when a task matches its description.
Can I use K8s Security Policies in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Cybereason-Public/owLSM --skill k8s-security-policies -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/k8s-security-policies, .gemini/skills/k8s-security-policies, .github/skills/k8s-security-policies and .opencode/skills/k8s-security-policies in your project.
What does K8s Security Policies need to run?
Going by SKILL.md and its folder, K8s Security Policies needs the command-line tools its instructions call (kubectl).
Does K8s Security Policies access the network?
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Is K8s Security Policies safe to install?
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
What licence does K8s Security Policies use?
K8s Security Policies is published under the GPL-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does K8s Security Policies use?
About 2k tokens (SKILL.md is roughly 7.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1k tokens, read only when the agent opens those files.
What are the alternatives to K8s Security Policies?
Skills that share tags, products or a category with K8s Security Policies: Detecting Privilege Escalation In Kubernetes Pods (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Implementing Rbac Hardening For Kubernetes (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Auditing Kubernetes Rbac Privilege Escalation (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Gke Workload Identity (google/skills, 21k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains K8s Security Policies?
Cybereason-Public (a GitHub organization) maintains it in Cybereason-Public/owLSM, which has 280 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 8, 2026.
Source: Cybereason-Public/owLSM on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.