K8s Security Audit
Installation
SKILL.md
phy-k8s-security-audit
Static security auditor for Kubernetes YAML manifests. Scans every Deployment, StatefulSet, DaemonSet, Pod, Job, CronJob, Role, ClusterRole, RoleBinding, ClusterRoleBinding, ServiceAccount, and NetworkPolicy in your repository against the CIS Kubernetes Benchmark v1.9 and Pod Security Standards (PSS). No cluster access required — works entirely on local manifest files.
Why Manifest Auditing Matters
- Tesla's Kubernetes cluster was cryptojacked because their dashboard had no auth and pods ran privileged
- Attackers with access to one container can escape to the node via
privileged: trueorhostPathmounts - Over-permissive RBAC (
cluster-admin) is the #1 post-exploit persistence technique automountServiceAccountToken: true(the default) leaks credentials into every pod