Skip to main content

hunting-helm-template-and-values-injection

Hunt injection through Kubernetes packaging templates and their values: an untrusted value rendered into a manifest without quoting so it injects YAML structure, a value that flows into a container command, an annotation, or an RBAC rule and grants more than intended, and a chart that renders privileged security context or host access from a caller-supplied value. Covers Helm-style templating where a values file or a user-supplied override is rendered into Kubernetes manifests, and where an unescaped or unconstrained value becomes structure, a command, or a permission. Use when charts render manifests from values that a tenant, a pipeline, or a user can influence. The untrusted value rendered into the manifest is the source, the template render is the sink, and the injected YAML structure or widened permission is the bug.

الانتقال إلى التثبيت

معلومات المصدر

المستودع
UnboundCompute/security-agent-skills
آخر نشاط في المصدر
٢٧ أغسطس ٢٠٢٦ في ١٩:١١
لغة SKILL.md المكتشفة
الإنجليزية
النجوم
٤
التفرعات
٢

خيارات التثبيت

يُحدَّد Prompt الذي يراجع المصدر أولًا بشكل افتراضي. يمكنك التبديل إلى أمر مباشر أو تنزيل نسخة محلية.

مراجعة ملفات المصدر

اقرأ SKILL.md وأي ملفات مرافقة يعرضها SkillsMP قبل أن تقرر التثبيت.