Hunt Kubernetes & Docker — API anonymous access, kubelet 10250 exec (SPDY/WebSocket, NOT plain POST) and the simpler /run primitive, etcd 2379 unauth, dashboard skip-login, RBAC misconfig, secret/SA-token abuse, docker.sock host escape, runc/container-escape (Leaky Vessels CVE-2024-21626), API-server-mediated nodes/proxy RCE, EphemeralContainers node-shell, bound/projected SA-token audience+expiry abuse, admission-controller bypass, Helm/Tiller remnants. Use when target runs containerized infra, exposes K8s ports (6443/10250/10255/2379/8443), or cloud metadata reveals K8s service accounts.
72
90%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Critical
Do not install without reviewing
Security
4 findings: 2 critical severity, 1 high severity, 1 medium severity. Installing this skill is not recommended: please review these findings carefully if you do intend to do so.
Detected a prompt injection in the skill instructions. The skill contains hidden or deceptive instructions that fall outside its stated purpose and attempt to override the agent’s safety guidelines or intended behavior.
This document is explicit offensive guidance with step-by-step instructions for achieving RCE, secret/credential exfiltration, and host escapes in Kubernetes/Docker environments.
Detected high-risk code patterns in the skill content — including its prompts, tool definitions, and resources — such as data exfiltration, backdoors, remote code execution, credential theft, system compromise, supply chain attacks, and obfuscation techniques.
This document is an offensive playbook giving explicit, runnable exploitation steps to obtain unauthorized RCE, credential exfiltration and host escape (e.g. kubelet /run and /exec commands, API-server proxy /run, etcd dumps, docker.sock privileged container creation, and runc CVE PoCs), demonstrating clear malicious intent and viable runtime mechanisms.
The skill handles credentials insecurely by requiring the agent to include secret values verbatim in its generated output. This exposes credentials in the agent’s context and conversation history, creating a risk of data exfiltration.
This skill explicitly instructs reading SA tokens and other secrets (e.g., cat /var/run/secrets/..., TOK=$(curl ...), echo "$TOKEN" | ... and using -H "Authorization: Bearer $TOKEN") and embeds them into commands/requests, which requires the LLM/agent to handle or output secret values verbatim.
The skill prompts the agent to compromise the security or integrity of the user’s machine by modifying system-level services or configurations, such as obtaining elevated privileges, altering startup scripts, or changing system-wide settings.
The skill contains explicit, actionable commands to create privileged containers (via the local docker.sock), patch/launch ephemeral/privileged pods, and execute remote/local kubelet/API run/exec leading to RCE and host filesystem access — i.e., it instructs changing system state and achieving host compromise if executed.
Low
Low-risk findings.
1 low severity finding. Worth noting, but not necessarily harmful.
The skill exposes the agent to untrusted, user-generated content from public third-party sources, creating a risk of indirect prompt injection. This includes browsing arbitrary URLs, reading social media posts or forum comments, and analyzing content from unknown websites.
The required runtime workflow is the “HUNT-K8S” penetration-testing procedure that sends attacker-chosen commands/inputs (e.g., `cmd=id`, `cmd=cat ...token`) to live Kubernetes kubelet/API/etcd endpoints, and therefore it necessarily ingests outsider-authored free text at runtime as the command payload.
646b72e
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.