container-security
Installation
SKILL.md
Container Security
Thin router for container and Kubernetes security assessments. Load the reference, workflow, or payload file you need — do not read all of them.
When to Use
- Scanning Docker/OCI images for CVEs (single image or pipeline)
- Generating or attesting SBOMs (Syft / CycloneDX / SPDX)
- Diffing SBOMs across releases to flag newly-introduced CVEs
- Auditing a live Kubernetes cluster (CIS / NSA / MITRE)
- Mapping K8s RBAC and finding privilege-escalation paths
- Reviewing NetworkPolicy coverage
- Authoring Falco / Tetragon runtime rules
- Analyzing or testing container escape vectors (authorized only)
- Docker daemon / host hardening review