Skip to content
Back to skills

Cloud K8s

ASecurity

Use for authorized cloud, container, and Kubernetes security assessment including metadata SSRF, IAM misconfig, container escape paths, and cluster RBAC review.

  • 434 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 23, 2026
ai-agentsbashdockerkubernetesawsgcpazuresecurity

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned September 23, 2026

npx -y skills add coco-research/coco --skill cloud-k8s --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Cloud K8s?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Cloud K8s
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/coco-research-cloud-k8s/badge)](https://www.skillsdirectory.com/skills/coco-research-cloud-k8s)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: cloud-k8s
description: Use for authorized cloud, container, and Kubernetes security assessment including metadata SSRF, IAM misconfig, container escape paths, and cluster RBAC review.
user-invocable: true
---

# Cloud / Container / Kubernetes Security

## 适用场景

- 云元数据 SSRF(169.254.169.254 / IMDS)
- IAM 过度权限、公开存储桶、错误安全组
- Docker/containerd 逃逸路径评估
- Kubernetes RBAC、Secrets、Admission、供应链镜像
- 容器镜像漏洞(可联动 `supply-chain-security/`)

## 工作流

### Phase 1 — 身份与边界

```text
□ 当前身份:云 AK/SK、K8s SA、节点 SSH?
□ 范围:单账号 / 单 cluster / 单 namespace
□ 网络档:authorized_target_only
```

### Phase 2 — 云控制面

```bash
# 示例(按厂商替换;MUST 在授权账号内)
aws sts get-caller-identity
aws s3 ls
# Azure / GCP 对应 identity 命令
```

```text
□ 公开桶 / 错误 ACL
□ 元数据:IMDSv1 vs v2;SSRF 链
□ 角色可扮演(PassRole)与横向
```

### Phase 3 — 容器

```text
□ 是否 privileged / hostPath / hostNetwork
□ capabilities(SYS_ADMIN 等)
□ 可写宿主机路径 → 逃逸候选
□ 镜像历史与已知 CVE → Trivy
```

### Phase 4 — Kubernetes

```bash
kubectl auth can-i --list
kubectl get pods,secrets,svc -A
kubectl get clusterrolebindings
```

```text
□ SA token 挂载与权限
□ 危险 admission webhook 缺失
□ etcd / dashboard 暴露
□ 网络策略是否默认放行
```

## 工具链

| 工具 | 用途 |
|------|------|
| kubectl | 集群交互 |
| trivy | 镜像/IaC |
| kube-bench / kubeaudit | CIS/配置 |
| pacu / scoutsuite | 云审计(授权) |
| nuclei | 已知云漏洞模板 |

## 参考

- `references/k8s-cloud-checklist.md`
- CTF 对照:`../../CTF-Sandbox-Orchestrator/competition-agent-cloud/`
- `../supply-chain-security/` `../pentest-tools/`

Files in this skill

  • SKILL.md1.9 KB
  • references/k8s-cloud-checklist.md401 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…