remediate-container-escape-k8s

Installation
SKILL.md

remediate-container-escape-k8s

What this closes

Pair skill for detect-container-escape-k8s.

This is the first Kubernetes detect → act → audit → re-verify loop in the repo. A container-escape finding flows in from stdin or a file; this skill resolves the live pod or workload selector from the cluster; dry-run prints the exact deny-all NetworkPolicy manifest that would be applied; --apply writes the policy after an out-of-band approval gate; --reverify proves the quarantine policy is still present and still shaped as expected.

Attack pattern it responds to

detect-container-escape-k8s emits findings for:

Installs
1
GitHub Stars
3
First Seen
Apr 20, 2026
remediate-container-escape-k8s — msaad00/cloud-ai-security-skills