Skip to main content
Jeden Skill in Manus ausführen
mit einem Klick

container-hunter

Sterne15
Forks7
Aktualisiert28. Juni 2026 um 16:46

Audits container / Kubernetes / OpenShift deployments for privileged pods, permissive SecurityContexts (runAsRoot, allowPrivilegeEscalation, hostPath mounts, hostNetwork, hostPID), missing NetworkPolicies, missing resource limits, lax RBAC (cluster-admin bindings), and Dockerfile patterns that leak creds or use moving-tag base images. Uses AWS CLI read verbs for EKS / ECS inventory; reads Dockerfile / K8s YAML from already-cloned repos; does NOT kubectl apply or describe live pods (delegate to operator). Use when the target runs containers (EKS / ECS / OpenShift / self-hosted K8s); or when `gitlab-cicd-hunter` / `secrets-in-code-hunter` surface container configs. Produces findings with CWE-732 / CWE-276 mapping and NetworkPolicy + SecurityContext + RBAC-hardening remediation.

Installation

Mit Codex oder Claude installieren Kopieren Sie diesen Prompt, fügen Sie ihn in Codex, Claude oder einen anderen Assistant ein und lassen Sie die Skill-Seite prüfen und installieren.

SKILL.md
readonly