ワンクリックで
review-security-k8s-main
Orchestrates comprehensive Kubernetes security reviews.
Codex または Claude でインストール この Prompt をコピーして Codex、Claude、または他のアシスタントに貼り付けると、Skill ページを確認してインストールできます。
メニュー
Orchestrates comprehensive Kubernetes security reviews.
Codex または Claude でインストール この Prompt をコピーして Codex、Claude、または他のアシスタントに貼り付けると、Skill ページを確認してインストールできます。
SOC 職業分類に基づく
Autonomously poll, triage, investigate, and resolve unaddressed open issues on our target GitHub repository strictly within authorized scope.
Configures, optimizes, and troubleshoots GKE ComputeClasses. Use when configuring Spot VMs with on-demand fallback, targeting specific accelerators (GPUs/TPUs) or machine families, restricting ComputeClass access, or debugging pending pods related to node pool auto-creation. Do not use for cluster-level Node Auto Provisioning configuration or general GKE cluster creation.
Audit, monitor, and debug the logging, tracing, metrics, and API/dashboard observability of the Platform Agent.
Standard Operating Procedure (SOP) for generating and updating secure, compliant, and cost-effective GKE manifests.
Systematic Standard Operating Procedure (SOP) for diagnosing GKE workload failures, crash loops, resource OOMs, mounting errors, and connectivity timeouts.
Reviews Kubernetes Pod security contexts for workload-level isolation and privilege escalation risks.
| name | review-security-k8s-main |
| description | Orchestrates comprehensive Kubernetes security reviews. |
Coordinate Kubernetes security review sub-agents, gather findings, and produce a summarized JSON report.
Invoke review-security-k8s-understand. Wait for summary.
Pass context and launch in parallel sub-agents:
review-security-k8s-rbacreview-security-k8s-nodesreview-security-k8s-networkreview-security-k8s-gatewayreview-security-k8s-namespacesreview-security-k8s-service-accountsreview-security-k8s-storagereview-security-k8s-admissionreview-security-k8s-podreview-security-k8s-agents-mainCRITICAL: Instruct each to output JSON:
[{"agent": "<skill>", "findings": [{"message": "<desc>", "file": "<name>", "line": "<num>"}]}]
(Return empty list if no findings). Wait for completion.
Evaluate the raw findings against the project context to determine actual risk. Filter out findings that are functionally required by the workload's specific role or adequately mitigated by broader architectural controls.
hostPath or privileged warnings for recognized infrastructure daemonsets (e.g., CSI drivers).NetworkPolicy warnings if the context confirms a strict Service Mesh is handling all routing and authorization.Merge the filtered findings into a single JSON array. Output MUST be valid JSON string (markdown blocks okay). Omit agents with no findings or return empty findings.