Skip to main content
Run any Skill in Manus
with one click

rbac-findings

Stars4
Forks2
UpdatedJuly 1, 2026 at 03:04

Surface Kubernetes RBAC hygiene and risk issues across a ConfigHub fleet with the cub-rbac CLI: wildcard permissions, privilege-escalation verbs, risky grants (secrets/exec/webhooks/CRDs), cluster-admin bindings, orphaned bindings, and unbound service accounts. Use for "audit our RBAC hygiene", "any wildcard roles?", "who has cluster-admin?", "find privilege escalation", "any orphaned role bindings?", "show RBAC risks in prod". Analysis-only — enforcement is server-side via Triggers/ApplyGates. Not for inventory/listing (use rbac-audit) or effective-access who-can queries (use rbac-whocan); not for live cluster scanning (use a cluster scanner).

Installation

Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.

File Explorer
2 files
SKILL.md
readonly