用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill cis-docker-v170-5-5命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
基于 SOC 职业分类
正在显示 SKILL.md
| name | cis-docker-v170-5.5 |
| description | Ensure that privileged containers are not used |
| category | cis-docker |
| version | 1.7.0 |
| author | cyberstrike-official |
| tags | ["cis","docker","runtime","configuration","privileged"] |
| cis_id | 5.5 |
| cis_benchmark | CIS Docker Benchmark v1.7.0 |
| tech_stack | ["docker"] |
| cwe_ids | ["CWE-250"] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
Using the --privileged flag provides all Linux kernel capabilities to the container to which it is applied and therefore overwrites the --cap-add and --cap-drop flags. For this reason you should ensure that it is not used.
The --privileged flag provides all capabilities to the container to which it is applied, and also lifts all the limitations enforced by the device cgroup controller. As a consequence this the container has most of the rights of the underlying host. This flag only exists to allow for specific use cases (for example running Docker within Docker) and should not generally be used.
If you start a container without the --privileged flag, it will not have excessive default capabilities.
You should run the command below:
docker ps --quiet --all | xargs docker inspect --format='{{ .Id }}: Privileged={{ .HostConfig.Privileged }}'
The above command should return Privileged=false for each container instance.
You should not run containers with the --privileged flag.
For example, do not start a container using the command below:
docker run --interactive --tty --privileged centos /bin/bash
False.
v8:
v7:
Manual