remediate-k8s-rbac-revoke

Installation
SKILL.md

remediate-k8s-rbac-revoke

What this closes

Pair skill for detect-privilege-escalation-k8s — specifically rule r3-rbac-self-grant (T1098: Account Manipulation). That rule is the only one in the detection bundle that hands the responder an unambiguous binding to revoke; the others identify an actor and an effect (token grant, pod exec, secret enum) but not a single binding the operator can safely delete.

This is the second Kubernetes detect → act → audit → re-verify loop in the repo, after remediate-container-escape-k8s. It lifts the same dual-audit, dry-run-default, deny-list, and incident-ID-gated --apply harness.

Scope honesty

Source finding Coverage
detect-privilege-escalation-k8s rule r3-rbac-self-grant Direct revocation — detector emits binding.type + binding.name; we revoke that binding
detect-privilege-escalation-k8s rules r1-secret-enum, r2-pod-exec, r4-token-self-grant Skipped with pointer — no specific binding in the finding; we emit skipped_no_binding_pointer and tell the operator to triage manually
detect-sensitive-secret-read-k8s (any rule) Skipped with pointer — same reason; this skill does not consume that producer at all (ACCEPTED_PRODUCERS enforces it)

A future PR can add a discovery mode (--discover-bindings-for-actor=NAME) that lists all RoleBindings + ClusterRoleBindings whose subjects[] reference an actor and emits a triage manifest. Discovery mode is intentionally out of scope here because it adds a large API surface (cluster-wide LIST + filter) and needs its own design pass on least-privilege scoping.

Inputs

Installs
1
GitHub Stars
3
First Seen
Apr 20, 2026
remediate-k8s-rbac-revoke — msaad00/cloud-ai-security-skills