k8s-security-redteam

Warn

Audited by Socket on Feb 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This is an explicit red-team playbook that intentionally documents high-risk techniques (credential harvesting from service account tokens and cloud IMDS, RBAC privilege escalation, host escapes via mount/nsenter, and creation of cluster-admin bindings). There is no evidence of hidden obfuscation or embedded malicious infrastructure in the provided text, but the actions described are powerful primitives for real attacks and must only be used with explicit written authorization. From a module-review perspective: the content is legitimate instructional material for offensive testing but represents a significant security risk if misused or automated without protections. Recommend strict access controls, audit/alerting on execution of these commands, and never run them outside an approved scope.

Confidence: 98%Severity: 75%
Audit Metadata
Analyzed At
Feb 28, 2026, 09:01 AM
Package URL
pkg:socket/skills-sh/foxj77%2Fclaude-code-skills%2Fk8s-security-redteam%2F@38a35709dfb9affb24e8d25f0e2bea9ee244e989