Agent skill

Defending Kubernetes

by trilwu in trilwu/secskills

Harden and monitor a Kubernetes cluster against the attacks that actually happen — RBAC least privilege and escalation paths, Pod Security Admission enforcement, network policy default-deny, secrets…

MITAuto-check passedDevOps & Cloud

Install Defending Kubernetes

skills CLI
$ npx skills add trilwu/secskills --skill defending-kubernetes -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trilwu/secskills defending-kubernetes --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/secskills-defense/skills/defending-kubernetes .claude/skills/defending-kubernetes && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
defending-kubernetes
GitHub stars
157
Token cost
~2.2k tokens
SKILL.md length
1,064 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Harden and monitor a Kubernetes cluster against the attacks that actually happen — RBAC least privilege and escalation paths, Pod Security Admission enforcement, network policy default-deny, secrets…

  • Works in 5 steps: RBAC least privilege → Pod Security Admission → Network policy default-deny → …
  • Reviewing a clusters security posture
  • SKILL.md covers When to Use, When NOT to Use, Enforce in Priority Order and Detection: Turn on the Audit Log, plus 3 more sections
  • Calls kubectl, jq and curl; reaches defuddle.md

What it does

Defending Kubernetes is an agent skill from trilwu/secskills. Harden and monitor a Kubernetes cluster against the attacks that actually happen — RBAC least privilege and escalation paths, Pod Security Admission enforcement, network policy default-deny, secrets and service-account token exposure, control-plane and kubelet exposure, and audit-log-based detection. Use when reviewing a cluster's security posture, responding to a suspected cluster compromise, deciding what to enforce and detect, or translating an attack path from attacking-eks-gke-aks into a defense.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Container orchestration, Authorization and RBAC and Translation. It works with Kubernetes and Google Kubernetes Engine. The repository describes itself as: Transform Claude Code into your personal security engineer. The licence is MIT.

When your agent uses it

  • Reviewing a clusters security posture
  • Responding to a suspected cluster compromise
  • Deciding what to enforce and detect
  • Translating an attack path from attacking-eks-gke-aks into a defense

Example prompts

  • “/defending-kubernetes”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. RBAC least privilege
  2. Pod Security Admission
  3. Network policy default-deny
  4. Service-account tokens and secrets
  5. Control-plane and kubelet exposure

What it can do on your machine

Read from SKILL.md and the folder at commit ca53957. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • kubectl
    • jq
    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • defuddle.md

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Defending Kubernetes loads about 2.2k tokens when it runs. Until then it costs about 132 tokens; SKILL.md has 1,064 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~132
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from trilwu/secskills at commit ca53957, republished under its MIT licence (© trilwu). 1,064 words, ~2,223 tokens.

Download SKILL.mdSave it as .claude/skills/defending-kubernetes/SKILL.md (or your agent's skills folder).
name
defending-kubernetes
description
Harden and monitor a Kubernetes cluster against the attacks that actually happen — RBAC least privilege and escalation paths, Pod Security Admission enforcement, network policy default-deny, secrets and service-account token exposure, control-plane and kubelet exposure, and audit-log-based detection. Use when reviewing a cluster's security posture, responding to a suspected cluster compromise, deciding what to enforce and detect, or translating an attack path from attacking-eks-gke-aks into a defense.
verified
2026-07-27

Defending Kubernetes

Kubernetes is insecure in useful defaults, not in exotic bugs. The attacks that land are RBAC that grants more than intended, pods that run privileged because nothing stops them, a flat pod network, and mounted service-account tokens with cluster-wide reach. Defense is mostly closing those, in priority order, and being able to see when someone tries.

This is the counterpart to attacking-eks-gke-aks and exploiting-containers: read those to know what the attacker does; use this to know what to enforce and what to watch.

When to Use

  • Reviewing a cluster's security posture or an admission/RBAC configuration
  • Responding to a suspected cluster compromise (post-triage)
  • Deciding what to enforce (Pod Security, network policy) and what to detect
  • Translating an offensive cluster finding into a concrete control
  • Hardening the control plane, kubelet, or etcd exposure

When NOT to Use

  • Attacking the cluster — use attacking-eks-gke-aks
  • Container escape and runtime internals specifically — use exploiting-containers / escaping-hardened-containers for the technique; return here for the control
  • The cloud IAM plane around the cluster (IRSA, workload identity, node role) — that is investigating-*-incidents / hardening-cloud-posture; a GKE/EKS/AKS incident usually needs both planes
  • Whether an alert is an incident — use triaging-security-alerts

Enforce in Priority Order

Order matters — these are ranked by how often the gap is the actual entry path.

1. RBAC least privilege

The most common real weakness. Look for the bindings that are escalation primitives regardless of how innocent they look:

bash
# Who can create pods anywhere? (→ mount any secret, run as any SA)
kubectl auth can-i create pods --all-namespaces --as=system:serviceaccount:ns:sa

# Subjects bound to cluster-admin
kubectl get clusterrolebindings -o json | \
  jq '.items[] | select(.roleRef.name=="cluster-admin") | .subjects'

The dangerous verbs are not just *. create pods lets a subject run a pod as any service account in the namespace and mount any secret — effectively namespace-admin. escalate and bind on roles let a subject grant themselves more than they hold. create on pods/exec, and access to secrets, serviceaccounts/token, and nodes/proxy are each escalation paths. Enumerate what subjects can do, not what their role is named.

2. Pod Security Admission

PodSecurityPolicy was removed in Kubernetes 1.25; the built-in replacement is Pod Security Admission, which enforces the three Pod Security Standards levels — privileged, baseline, restricted — per namespace via labels:

yaml
# Namespace label: enforce the restricted profile, and warn/audit on violations
pod-security.kubernetes.io/enforce: restricted
pod-security.kubernetes.io/warn: restricted
pod-security.kubernetes.io/audit: restricted

restricted blocks the pod configurations that make escape and privilege escalation easy: privileged containers, host namespaces (hostPID, hostNetwork, hostIPC), host-path mounts, running as root, added capabilities. A cluster with no enforced profile is one securityContext.privileged: true away from a node takeover. If you need policy beyond the three levels (image provenance, registry allow-lists), that is an external admission controller (Kyverno, OPA Gatekeeper) — note it, do not pretend PSA covers it.

3. Network policy default-deny

By default every pod can reach every other pod. A default-deny ingress policy per namespace, with explicit allows, is what stops a single compromised pod from becoming lateral movement. Confirm the CNI actually enforces NetworkPolicy — some configurations accept the objects and enforce nothing, which is worse than none because it looks covered.

4. Service-account tokens and secrets
  • automountServiceAccountToken: false on pods that do not call the API. A mounted token plus a permissive RBAC binding is the standard in-cluster pivot.
  • Kubernetes Secrets are base64, not encrypted, in etcd unless encryption-at-rest is configured. Confirm it is.
  • Look for tokens and cloud credentials passed as env vars — they leak into logs and crash dumps.
5. Control-plane and kubelet exposure
  • The API server should not be internet-facing without authn/authz and, ideally, network restriction. Anonymous auth must be off.
  • The kubelet read-only port (10255) and the authenticated port (10250) must not be reachable from workloads; nodes/proxy RBAC and an exposed 10250 are a direct route to command execution on nodes.
  • etcd must require mutual TLS — etcd access is game-over, it holds every secret.
Show full SKILL.md (481 more words)Show less

Detection: Turn on the Audit Log

Most clusters run with no meaningful audit policy, so there is nothing to investigate after the fact. A cluster without an audit policy configured is the Kubernetes version of GCP Data Access logging being off — the activity is simply not recorded.

High-value audit signals:

  • exec, attach, and port-forward into pods — interactive access
  • Secret get/list at scale, especially cluster-wide
  • create/update on clusterrolebindings and rolebindings
  • Pods created with privileged, host namespaces, or host-path mounts
  • Anonymous or system:unauthenticated requests that succeed
  • Service-account token creation via the TokenRequest API

On managed clusters the audit log ships to the cloud logging plane (GKE → Cloud Audit Logs, EKS → CloudWatch, AKS → Azure Monitor), which is where the investigation joins up with the investigating-*-incidents skills.

Rationalizations to Reject

  • "The role isn't named admin, so it's fine." Names are irrelevant. create pods or secrets get in a namespace is namespace-admin in effect. Enumerate capabilities, not titles.
  • "We enforce Pod Security, so containers are contained." Only if the profile is restricted and actually enforced, not merely warn. A baseline or audit-only label stops almost none of the escape paths.
  • "NetworkPolicies are defined, so the network is segmented." Only if the CNI enforces them. Verify enforcement, not the presence of the objects.
  • "Secrets are in etcd, so they're protected." They are base64 unless encryption-at-rest is on. Anyone who can read etcd or get secrets has them.
  • "It's a managed cluster, the provider secures it." The provider secures the control plane it runs; RBAC, Pod Security, network policy, and workload identity are yours. Shared responsibility does not include your bindings.
  • "No alerts fired." Check whether an audit policy exists at all before reading silence as safety.

Reading External Sources

Fetch public advisories, specifications, and vendor reports as Markdown:

bash
curl -sL "https://defuddle.md/<url>"      # scheme in the path is optional

This strips page boilerplate — roughly 78% fewer tokens on a prose page — and returns the full text rather than a summary, so you can grep it and trust a negative result.

Three things it is not for. Fetch JSON and API responses raw, because readability extraction mangles structured data. Fetch authenticated or JavaScript-rendered pages directly, because it retrieves them anonymously. And never route adversary infrastructure (phishing links, C2, malware hosting), client-owned hosts, or engagement URLs through it — the request leaves your machine to a third party, and for live adversary infrastructure it also tips off the operator.

Some sites block the extractor and return an error blob rather than the page — {"error":"Failed to fetch: 418 I'm a teapot"} from freedesktop.org, for instance. That is the fetch being refused, not the source saying the thing does not exist. Re-fetch the URL directly before drawing any conclusion from it.

References

  • attacking-eks-gke-aks — the attack paths these controls close
  • exploiting-containers, escaping-hardened-containers — the escape techniques Pod Security aims to prevent
  • hardening-cloud-posture — the cloud IAM plane around the cluster
  • engineering-detections — turning the audit signals above into rules
  • investigating-aws-incidents / investigating-gcp-incidents — where a managed-cluster audit trail leads

© trilwu, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in secskills-defense/skills/defending-kubernetes of trilwu/secskills.

Open the folder on GitHubat commit ca53957

Compare with similar skills

Defending Kubernetes next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Defending Kubernetes compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Defending Kubernetes this skilltrilwu/secskills157—~2.2kAutomated safety check: PassMIT
Mirrord Operatoraiskillstore/marketplace433—~4.6kAutomated safety check: PassNone
Securing Kubernetes On Cloudmukul975/Anthropic-Cybersecurity-Skills34k—~3.3kAutomated safety check: PassApache-2.0
Gke Workload Identitygoogle/skills21k—~4.4kAutomated safety check: PassApache-2.0
Azure Bastion Jitvinayaklatthe/microsoft-security-skills175—~2.2kAutomated safety check: PassMIT
Gke Batch Hpcgoogle/skills21k—~1.4kAutomated safety check: PassApache-2.0

Similar skills

  • Mirrord Operator

    aiskillstore/marketplace

    Help users install and configure the mirrord Operator for team/enterprise environments.

    433 GitHub stars~4.6k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Securing Kubernetes On Cloud

    mukul975/Anthropic-Cybersecurity-Skills

    Hardens managed Kubernetes clusters on EKS, AKS, and GKE by implementing Pod Security Standards, network policies, workload identity (IRSA for EKS, Workload Identity for GKE, Managed Identities for…

    34k GitHub stars~3.3k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Official

    Configures and diagnoses Workload Identity Federation for GKE authentication failures for Pods (403 "iam.serviceAccounts.getAccessToken" / permission denied, "could not find default credentials", or…

    21k GitHub stars~4.4k tokensUpdated today
    Backend & APIsAuto-check passed
  • Azure Bastion Jit

    vinayaklatthe/microsoft-security-skills

    Guidance for secure remote VM management in Azure using Azure Bastion combined with Defender for Cloud just-in-time (JIT) VM access.

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    DevOps & CloudAuto-check passed
  • Gke Batch Hpc

    google/skills

    Official

    Runs batch and HPC workloads on GKE, utilizing job queues and parallel processing.

    21k GitHub stars~1.4k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Dt Obs GCP

    Dynatrace/dynatrace-for-ai

    GCP cloud resources including Compute Engine, GKE, Cloud Run, Pub/Sub, VPC networking, DNS, IAM, Secret Manager, and monitoring.

    163 GitHub stars~2.5k tokensUpdated 9 days ago
    DevOps & CloudAuto-check passed

More from trilwu/secskills

All 50 skills in this repo
  • Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.

    157 GitHub stars~3.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.

    157 GitHub stars~3.1k tokensUpdated 1 mo ago
    Auto-check: notes
  • Securing AI Systems

    trilwu/secskills

    Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…

    157 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing Binaries

    trilwu/secskills

    Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.

    157 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing Go Binaries

    trilwu/secskills

    Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…

    157 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing iOS Binaries

    trilwu/secskills

    Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…

    157 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Defending Kubernetes

What does Defending Kubernetes do?

Harden and monitor a Kubernetes cluster against the attacks that actually happen — RBAC least privilege and escalation paths, Pod Security Admission enforcement, network policy default-deny, secrets…. Defending Kubernetes is an agent skill from trilwu/secskills. Harden and monitor a Kubernetes cluster against the attacks that actually happen — RBAC least privilege and escalation paths, Pod Security Admission enforcement, network policy default-deny, secrets and service-account token exposure, control-plane and kubelet exposure, and audit-log-based detection.

When should I use Defending Kubernetes?

Defending Kubernetes fits situations like: reviewing a clusters security posture; responding to a suspected cluster compromise; deciding what to enforce and detect; translating an attack path from attacking-eks-gke-aks into a defense.

How do I install Defending Kubernetes in Claude Code?

Run `npx skills add trilwu/secskills --skill defending-kubernetes -a claude-code`. Or copy the skill folder (secskills-defense/skills/defending-kubernetes in trilwu/secskills) into .claude/skills/defending-kubernetes in your project. Claude Code loads it when a task matches its description.

How do I install Defending Kubernetes in Codex?

Run `npx skills add trilwu/secskills --skill defending-kubernetes -a codex`. Or copy the skill folder (secskills-defense/skills/defending-kubernetes in trilwu/secskills) into .agents/skills/defending-kubernetes in your project. Codex loads it when a task matches its description.

Can I use Defending Kubernetes in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trilwu/secskills --skill defending-kubernetes -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/defending-kubernetes, .gemini/skills/defending-kubernetes, .github/skills/defending-kubernetes and .opencode/skills/defending-kubernetes in your project.

What does Defending Kubernetes need to run?

Going by SKILL.md and its folder, Defending Kubernetes needs the command-line tools its instructions call (kubectl, jq and curl).

Does Defending Kubernetes access the network?

SKILL.md names 1 domain. In commands or code: defuddle.md; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Defending Kubernetes safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Defending Kubernetes use?

Defending Kubernetes is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Defending Kubernetes use?

About 2.2k tokens (SKILL.md is roughly 8.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Defending Kubernetes?

Skills that share tags, products or a category with Defending Kubernetes: Mirrord Operator (aiskillstore/marketplace, 433 stars), Securing Kubernetes On Cloud (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Gke Workload Identity (google/skills, 21k stars) and Azure Bastion Jit (vinayaklatthe/microsoft-security-skills, 175 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Defending Kubernetes?

trilwu (a GitHub user) maintains it in trilwu/secskills, which has 157 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on September 4, 2026.

Source: trilwu/secskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.