kubernetes-pentesting
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONCREDENTIALS_UNSAFEDATA_EXFILTRATIONPERSISTENCE
Full Analysis
- [COMMAND_EXECUTION]: The skill provides a large volume of shell commands designed to probe, enumerate, and exploit Kubernetes API servers, Kubelet APIs, and node services.- [PRIVILEGE_ESCALATION]: It includes specific instructions for container-to-host escapes using privileged security contexts and the nsenter command to access the host namespace. It also details RBAC escalation methods such as creating admin tokens or binding high-privilege roles.- [CREDENTIALS_UNSAFE]: The playbook guides the extraction of sensitive data including service account tokens, kubeconfig files, and secrets from the container registry and etcd database.- [DATA_EXFILTRATION]: The instructions include commands to harvest temporary cloud credentials from AWS, GCP, and Azure metadata endpoints (IMDS) from within a compromised pod.- [PERSISTENCE]: The skill documents the use of static pod manifests on nodes to maintain persistent access while bypassing API server admission controllers.
Audit Metadata