k8s-security-benchmark
Warn
Audited by Socket on Apr 20, 2026
1 alert found:
SecuritySecurityexamples/insecure-cluster.json
MEDIUMSecurityMEDIUM
examples/insecure-cluster.json
No covert malware behavior is present in this manifest; it is explicitly an insecure training/test fixture. However, it contains multiple critically dangerous Kubernetes security misconfigurations (privileged root container with SYS_ADMIN/NET_ADMIN, hostNetwork/hostPID/hostIPC enabled, hostPort exposure, plaintext secret-like env vars, and cluster-admin RBAC granted to system:authenticated). Treat as extremely high security risk if deployed outside a controlled test environment.
Confidence: 86%Severity: 94%
Audit Metadata