remediate-container-escape-k8s
Installation
SKILL.md
remediate-container-escape-k8s
What this closes
Pair skill for detect-container-escape-k8s.
This is the first Kubernetes detect → act → audit → re-verify loop in the
repo. A container-escape finding flows in from stdin or a file; this skill
resolves the live pod or workload selector from the cluster; dry-run prints the
exact deny-all NetworkPolicy manifest that would be applied; --apply writes
the policy after an out-of-band approval gate; --reverify proves the
quarantine policy is still present and still shaped as expected.
Attack pattern it responds to
detect-container-escape-k8s emits findings for: