kubernetes-pentesting

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONCREDENTIALS_UNSAFEDATA_EXFILTRATIONPERSISTENCE
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides a large volume of shell commands designed to probe, enumerate, and exploit Kubernetes API servers, Kubelet APIs, and node services.- [PRIVILEGE_ESCALATION]: It includes specific instructions for container-to-host escapes using privileged security contexts and the nsenter command to access the host namespace. It also details RBAC escalation methods such as creating admin tokens or binding high-privilege roles.- [CREDENTIALS_UNSAFE]: The playbook guides the extraction of sensitive data including service account tokens, kubeconfig files, and secrets from the container registry and etcd database.- [DATA_EXFILTRATION]: The instructions include commands to harvest temporary cloud credentials from AWS, GCP, and Azure metadata endpoints (IMDS) from within a compromised pod.- [PERSISTENCE]: The skill documents the use of static pod manifests on nodes to maintain persistent access while bypassing API server admission controllers.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 02:13 PM
Security Audit — agent-trust-hub — kubernetes-pentesting