Back to skills
SKILL.md
Cloud K8s
ASecurityUse for authorized cloud, container, and Kubernetes security assessment including metadata SSRF, IAM misconfig, container escape paths, and cluster RBAC review.
- 8 stars
- 0 votes
- 0 copies
- 2 views
- Added September 12, 2026
Security analysis
100/100Pro scans all 2 files and shows the line behind each finding
npx -y skills add stanfish06/skillquarium --skill cloud-k8s --agent claude-codeAre you the author of Cloud K8s?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/stanfish06-cloud-k8s)---
name: cloud-k8s
description: Use for authorized cloud, container, and Kubernetes security assessment including metadata SSRF, IAM misconfig, container escape paths, and cluster RBAC review.
---
# Cloud / Container / Kubernetes Security
## ACTION REQUIRED(读完后立刻执行)
1. `NOW`: 读取 `../reverse-skill-router/field-journal/precedent-pentest.md` — **云/K8s 测试必须书面授权**
2. `NOW`: case-init + scope;明确账号边界、禁止破坏性操作
3. `NOW`: 确认是云元数据/容器/K8s/IAM,而非普通 Web 扫(后者 `pentest-tools/`)
4. `NEXT`: tool-index;kubectl/aws/gcloud 等多为手动安装
5. `ACT`: 从「身份与暴露面」开始,禁止默认全网扫描
## 适用场景
- 云元数据 SSRF(169.254.169.254 / IMDS)
- IAM 过度权限、公开存储桶、错误安全组
- Docker/containerd 逃逸路径评估
- Kubernetes RBAC、Secrets、Admission、供应链镜像
- 容器镜像漏洞(可联动 `supply-chain-security/`)
## 工作流
### Phase 1 — 身份与边界
```text
□ 当前身份:云 AK/SK、K8s SA、节点 SSH?
□ 范围:单账号 / 单 cluster / 单 namespace
□ 网络档:authorized_target_only
```
### Phase 2 — 云控制面
```bash
# 示例(按厂商替换;MUST 在授权账号内)
aws sts get-caller-identity
aws s3 ls
# Azure / GCP 对应 identity 命令
```
```text
□ 公开桶 / 错误 ACL
□ 元数据:IMDSv1 vs v2;SSRF 链
□ 角色可扮演(PassRole)与横向
```
### Phase 3 — 容器
```text
□ 是否 privileged / hostPath / hostNetwork
□ capabilities(SYS_ADMIN 等)
□ 可写宿主机路径 → 逃逸候选
□ 镜像历史与已知 CVE → Trivy
```
### Phase 4 — Kubernetes
```bash
kubectl auth can-i --list
kubectl get pods,secrets,svc -A
kubectl get clusterrolebindings
```
```text
□ SA token 挂载与权限
□ 危险 admission webhook 缺失
□ etcd / dashboard 暴露
□ 网络策略是否默认放行
```
## 工具链
| 工具 | 用途 | 自举 |
|------|------|------|
| kubectl | 集群交互 | 手动 |
| trivy | 镜像/IaC | bootstrap `trivy` 若可用 |
| kube-bench / kubeaudit | CIS/配置 | 手动 |
| pacu / scoutsuite | 云审计(授权) | 手动 |
| nuclei | 已知云漏洞模板 | bootstrap nmap/nuclei 生态 |
## 参考
- `references/k8s-cloud-checklist.md`
- CTF 对照:`../../CTF-Sandbox-Orchestrator/competition-agent-cloud/`
- `../supply-chain-security/` `../pentest-tools/`
## 路由上下文
**上游**: MASTER R23
**下游**: 拿到节点 shell → `attack-chain` / `windows-ad`;镜像漏洞 → supply-chain
**MUST NOT**: 未授权扫公有云其他租户
## 任务完成自检
- [ ] 是否限定在授权账号/cluster?
- [ ] 发现是否含复现与影响?
- [ ] 是否避免破坏性操作?
- [ ] 报告 / journal?Files in this skill
- SKILL.md
- references/k8s-cloud-checklist.md
Attribution
Comments
Loading comments…