AgentStack
SKILL verified Apache-2.0 Self-run

Container

skill-mingyiseclab-mingyi-atlas-container · by MingyiSecLab

Container / Kubernetes attack category — pod escape, RBAC abuse, runtime CVE exploitation, socket-mount escape. Routing skill: identify the surface (pod-internal RCE vs API-level vs build-pipeline), then load the matching sub-skill.

No reviews yet
0 installs
21 views
0.0% view→install

Install

$ agentstack add skill-mingyiseclab-mingyi-atlas-container

✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

Are you the author of Container? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Container / Kubernetes Attack Category

This is a routing skill for cloud-native engagements. Identify the surface, then load the matching sub-skill.

Sub-skills

| Sub-skill | Covers | When to load | |---|---|---| | k8s-pod-escape | Privileged container, hostPath escape, hostPID + SYS_PTRACE, runC CVE chains, cgroup release agent | RCE inside a pod, goal is node compromise | load_skill("/skills/standard/cloud/container/k8s-pod-escape/SKILL.md") | | k8s-rbac-abuse | auth can-i --list, pods/exec on privileged pods, secrets get/list, escalate verb, bind verb, impersonate, nodes/proxy | You have a ServiceAccount token; goal is cluster-admin | load_skill("/skills/standard/cloud/container/k8s-rbac-abuse/SKILL.md") | | docker-socket-mount | /var/run/docker.sock or containerd socket mounted in → instant host root | CI runners, ArgoCD/Flux, DinD, Jenkins agents | load_skill("/skills/standard/cloud/container/docker-socket-mount/SKILL.md") | | container-cve | Catalog of high-impact runtime CVEs — Leaky Vessels, runC 2019-5736, BuildKit chain, CRI-O 2022-0811 | Container runtime version fingerprinted | load_skill("/skills/standard/cloud/container/container-cve/SKILL.md") |

Quick routing

Container target identified?
├── You have RCE in a pod / container         → k8s-pod-escape
├── You have a Kubernetes SA token            → k8s-rbac-abuse
├── Socket mounted (`docker.sock`, etc.)      → docker-socket-mount
├── Runtime version is old / vulnerable       → container-cve
└── Unknown / all of above                     → start with k8s-pod-escape's Phase 1

Tooling

| Tool | Use | |---|---| | kubectl | API-level enumeration and abuse | | kube-hunter | Automated cluster vulnerability scan | | kdigger | In-cluster recon (Quarkslab) | | peirates | Kubernetes-specific privilege escalation | | botb | Container break-out (Brad-Beam et al.) | | nsenter | Cross-namespace process / mount entry | | crictl / ctr / nerdctl | containerd / CRI direct access |

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet — be the first.

Versions

  • v0.1.0 Imported from the upstream source.