Skip to main content
Ejecuta cualquier Skill en Manus
con un clic

container-hunter

Estrellas15
Forks7
Actualizado28 de junio de 2026 a las 16:46

Audits container / Kubernetes / OpenShift deployments for privileged pods, permissive SecurityContexts (runAsRoot, allowPrivilegeEscalation, hostPath mounts, hostNetwork, hostPID), missing NetworkPolicies, missing resource limits, lax RBAC (cluster-admin bindings), and Dockerfile patterns that leak creds or use moving-tag base images. Uses AWS CLI read verbs for EKS / ECS inventory; reads Dockerfile / K8s YAML from already-cloned repos; does NOT kubectl apply or describe live pods (delegate to operator). Use when the target runs containers (EKS / ECS / OpenShift / self-hosted K8s); or when `gitlab-cicd-hunter` / `secrets-in-code-hunter` surface container configs. Produces findings with CWE-732 / CWE-276 mapping and NetworkPolicy + SecurityContext + RBAC-hardening remediation.

Instalación

Instalar con Codex o Claude Copia este prompt, pégalo en Codex, Claude u otro asistente, y deja que revise la página de la skill y la instale por ti.

SKILL.md
readonly