K8s Security Policies
Cybereason-Public/owLSM
Comprehensive guide for implementing NetworkPolicy, PodSecurityPolicy, RBAC, and Pod Security Standards in Kubernetes.
Istio Service Mesh 安全策略绕过。当目标 K8s 集群使用 Istio、请求被 AuthorizationPolicy 拒绝(403 RBAC denied)、或发现 Envoy sidecar 时使用。核心手法:UID 1337 绕过 Envoy。任何在 K8s 中遇到 Istio 策略阻拦、Service Mesh 限制、或 Envoy 相关安全控制的场景都应使用此技能
$ npx skills add wgpsec/AboutSecurity --skill k8s-istio-bypass -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install wgpsec/AboutSecurity k8s-istio-bypass --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/wgpsec/AboutSecurity.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cloud/k8s-istio-bypass .claude/skills/k8s-istio-bypass && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "k8s-istio-bypass" agent skill from https://github.com/wgpsec/AboutSecurity/tree/master/skills/cloud/k8s-istio-bypass into .claude/skills/k8s-istio-bypass/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "k8s-istio-bypass", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/wgpsec/AboutSecurity/tree/master/skills/cloud/k8s-istio-bypassType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add wgpsec/AboutSecurity --skill k8s-istio-bypass -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install wgpsec/AboutSecurity k8s-istio-bypass --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/wgpsec/AboutSecurity.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/cloud/k8s-istio-bypass .agents/skills/k8s-istio-bypass && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "k8s-istio-bypass" agent skill from https://github.com/wgpsec/AboutSecurity/tree/master/skills/cloud/k8s-istio-bypass into .agents/skills/k8s-istio-bypass/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "k8s-istio-bypass", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add wgpsec/AboutSecurity --skill k8s-istio-bypass -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install wgpsec/AboutSecurity k8s-istio-bypass --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/wgpsec/AboutSecurity.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/cloud/k8s-istio-bypass .cursor/skills/k8s-istio-bypass && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "k8s-istio-bypass" agent skill from https://github.com/wgpsec/AboutSecurity/tree/master/skills/cloud/k8s-istio-bypass into .cursor/skills/k8s-istio-bypass/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "k8s-istio-bypass", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/wgpsec/AboutSecurity.git --path skills/cloud/k8s-istio-bypass--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add wgpsec/AboutSecurity --skill k8s-istio-bypass -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install wgpsec/AboutSecurity k8s-istio-bypass --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/wgpsec/AboutSecurity.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/cloud/k8s-istio-bypass .gemini/skills/k8s-istio-bypass && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "k8s-istio-bypass" agent skill from https://github.com/wgpsec/AboutSecurity/tree/master/skills/cloud/k8s-istio-bypass into .gemini/skills/k8s-istio-bypass/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "k8s-istio-bypass", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install wgpsec/AboutSecurity k8s-istio-bypassInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add wgpsec/AboutSecurity --skill k8s-istio-bypass -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/wgpsec/AboutSecurity.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/cloud/k8s-istio-bypass .github/skills/k8s-istio-bypass && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "k8s-istio-bypass" agent skill from https://github.com/wgpsec/AboutSecurity/tree/master/skills/cloud/k8s-istio-bypass into .github/skills/k8s-istio-bypass/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "k8s-istio-bypass", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add wgpsec/AboutSecurity --skill k8s-istio-bypass -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install wgpsec/AboutSecurity k8s-istio-bypass --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/wgpsec/AboutSecurity.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/cloud/k8s-istio-bypass .opencode/skills/k8s-istio-bypass && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "k8s-istio-bypass" agent skill from https://github.com/wgpsec/AboutSecurity/tree/master/skills/cloud/k8s-istio-bypass into .opencode/skills/k8s-istio-bypass/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "k8s-istio-bypass", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
k8s-istio-bypassIstio Service Mesh 安全策略绕过。当目标 K8s 集群使用 Istio、请求被 AuthorizationPolicy 拒绝(403 RBAC denied)、或发现 Envoy sidecar 时使用。核心手法:UID 1337 绕过 Envoy。任何在 K8s 中遇到 Istio 策略阻拦、Service Mesh 限制、或 Envoy 相关安全控制的场景都应使用此技能
K8s Istio Bypass is an agent skill from wgpsec/AboutSecurity. Istio Service Mesh 安全策略绕过。当目标 K8s 集群使用 Istio、请求被 AuthorizationPolicy 拒绝(403 RBAC denied)、或发现 Envoy sidecar 时使用。核心手法:UID 1337 绕过 Envoy。任何在 K8s 中遇到 Istio 策略阻拦、Service Mesh 限制、或 Envoy 相关安全控制的场景都应使用此技能
Its SKILL.md is about 730 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Backend & APIs, covering Container orchestration, Microservices and Authorization and RBAC. It works with Kubernetes. The repository describes itself as: Everything for pentest. | 渗透测试知识库,以 AI Agent 可执行的格式沉淀安全方法论。
Read from SKILL.md and the folder at commit 914ffb5. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
curlFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
K8s Istio Bypass loads about 727 tokens when it runs. Until then it costs about 54 tokens; SKILL.md has 103 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Without a licence we can't republish the file, so here is its outline and opening line. It has 103 words (~727 tokens).
“Istio 通过 Envoy sidecar 实现流量管理和安全策略。但 Istio 的架构中有一个根本性的设计缺陷可以被利用:Envoy 以 UID 1337 运行,而 iptables 规则会排除 UID 1337 的流量以避免死循环——这意味着以该 UID 身份发出的请求完全绕过 Envoy,所有 Istio 策略不再生效。”
Just SKILL.md in skills/cloud/k8s-istio-bypass of wgpsec/AboutSecurity.
Open the folder on GitHubat commit 914ffb5
K8s Istio Bypass next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| K8s Istio Bypass this skillwgpsec/AboutSecurity | 1.8k | — | ~727 | Automated safety check: Pass | None | |
| K8s Security PoliciesCybereason-Public/owLSM | 280 | 12 repos | ~2k | Automated safety check: Pass | GPL-2.0 | |
| Implementing Rbac Hardening For Kubernetesmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2k | Automated safety check: Pass | Apache-2.0 | |
| Auditing Kubernetes Rbac Privilege Escalationmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | |
| Gke Workload Identitygoogle/skills | 21k | — | ~4.4k | Automated safety check: Pass | Apache-2.0 | |
| Ak Cloud Deployyaalalabs/agent-kernel | 192 | — | ~14k | Automated safety check: Pass | Apache-2.0 |
Cybereason-Public/owLSM
Comprehensive guide for implementing NetworkPolicy, PodSecurityPolicy, RBAC, and Pod Security Standards in Kubernetes.
mukul975/Anthropic-Cybersecurity-Skills
Hardens Kubernetes RBAC by designing least-privilege Roles and ClusterRoles, auditing RoleBindings, eliminating cluster-admin sprawl, separating service accounts, and integrating an external OIDC…
mukul975/Anthropic-Cybersecurity-Skills
Finds over-permissive RBAC roles and service-account token abuse paths in a Kubernetes cluster using kubectl auth can-i, rbac-police, kubectl-who-can, and rakkess, tracing which subjects can…
google/skills
Configures and diagnoses Workload Identity Federation for GKE authentication failures for Pods (403 "iam.serviceAccounts.getAccessToken" / permission denied, "could not find default credentials", or…
yaalalabs/agent-kernel
Deploy an Agent Kernel project to AWS, Azure, or GCP using Terraform modules, or to any Kubernetes cluster (on-prem, baremetal, EKS) using the official Helm chart.
jeremylongshore/tons-of-skills-marketplace
Analyze kubernetes rbac analyzer operations. An agent skill from jeremylongshore/tons-of-skills-marketplace.
wgpsec/AboutSecurity
A skill your agent uses whenever the user asks to add, absorb, migrate, port, update, merge, compare, or extract security knowledge into the AboutSecurity repository from any external resource such…
wgpsec/AboutSecurity
AD 域环境持久化技术。当已获取域管/本地管理员权限、需要建立持久访问以确保重启或密码更改后仍能回到目标环境时使用。覆盖主机级持久化(计划任务/注册表Run/COM劫持/WMI事件订阅/Windows服务/启动文件夹)、域级持久化(Golden Ticket/Silver Ticket/Skeleton…
wgpsec/AboutSecurity
APT 模拟与情报驱动红队方法论。基于已知 APT 组织的 TTP(MITRE ATT&CK)设计红队行动计划。当需要模拟特定威胁组织、设计高仿真攻击演练、或根据威胁情报制定攻击策略时使用
wgpsec/AboutSecurity
ArgoCD 后渗透方法论:Redis缓存投毒集群接管、SSO认证绕过、未授权API枚举、恶意Application部署、Webhook SSRF、默认凭据利用。
wgpsec/AboutSecurity
C2 Beacon 配置提取与分析。当捕获到 Cobalt Strike/Sliver/Havoc 等 C2 框架的 Beacon 样本、内存 dump、或网络流量时使用。提取 C2 地址、通信协议、Malleable Profile、Watermark 等关键情报。红队视角:了解蓝队如何从 Beacon 提取 IOC 以改进 C2 OPSEC
wgpsec/AboutSecurity
C2框架免杀方法论:分析 C2 源码、搜索检测规则(YARA/Sigma/Snort)、逐规则分析、修改源码绕过检测。当遇到 YARA/Sigma/Snort 规则触发告警、beacon/implant 被杀软检测到时使用。第一步:确认 implant/beacon 语言和架构;第二步:搜索对应检测规则并逐规则分析修改
Works with
Categories
Istio Service Mesh 安全策略绕过。当目标 K8s 集群使用 Istio、请求被 AuthorizationPolicy 拒绝(403 RBAC denied)、或发现 Envoy sidecar 时使用。核心手法:UID 1337 绕过 Envoy。任何在 K8s 中遇到 Istio 策略阻拦、Service Mesh 限制、或 Envoy 相关安全控制的场景都应使用此技能. K8s Istio Bypass is an agent skill from wgpsec/AboutSecurity.
K8s Istio Bypass fits situations like: tasks that involve Container orchestration; tasks that involve Microservices; tasks that involve Authorization and RBAC.
Run `npx skills add wgpsec/AboutSecurity --skill k8s-istio-bypass -a claude-code`. Or copy the skill folder (skills/cloud/k8s-istio-bypass in wgpsec/AboutSecurity) into .claude/skills/k8s-istio-bypass in your project. Claude Code loads it when a task matches its description.
Run `npx skills add wgpsec/AboutSecurity --skill k8s-istio-bypass -a codex`. Or copy the skill folder (skills/cloud/k8s-istio-bypass in wgpsec/AboutSecurity) into .agents/skills/k8s-istio-bypass in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add wgpsec/AboutSecurity --skill k8s-istio-bypass -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/k8s-istio-bypass, .gemini/skills/k8s-istio-bypass, .github/skills/k8s-istio-bypass and .opencode/skills/k8s-istio-bypass in your project.
Going by SKILL.md and its folder, K8s Istio Bypass needs the command-line tools its instructions call (curl).
SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
No licence was found for K8s Istio Bypass or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.
About 727 tokens (SKILL.md is roughly 2.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with K8s Istio Bypass: K8s Security Policies (Cybereason-Public/owLSM, 280 stars), Implementing Rbac Hardening For Kubernetes (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Auditing Kubernetes Rbac Privilege Escalation (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Gke Workload Identity (google/skills, 21k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
wgpsec (a GitHub organization) maintains it in wgpsec/AboutSecurity, which has 1,778 GitHub stars. The repository holds 64 skills in this directory. The repository was last updated on October 10, 2026.
Source: wgpsec/AboutSecurity on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.