offensive-k8s-attacks skillB
offensive-k8s-attacks is agent-read markdown (skill) from snailsploit/claude-red: Kubernetes cluster attack techniques covering the full attack lifecycle from initial foothold in a pod to cluster-wide compromise. Covers service account token theft and impersonation, RBAC misconfiguration exploitation including wildcard permissions and privilege escalation via role binding, direct etcd access for secret extraction, kubelet API abuse on port 10250 and read-only port 10255, pod escape via hostPID hostNetwork and hostPath volume mounts, Kubernetes secrets enumeration and decoding.
Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.
What the file says
# Kubernetes Cluster Attacks You have access to a Kubernetes environment, either through a compromised pod, stolen kubeconfig, or exposed API server. Your objective is to escalate privileges, move laterally, and compromise the cluster or underlying cloud infrastructure. Kubernetes security depends on RBAC policies, network policies, admission controllers, pod security standards, and cloud IAM integration. Each misconfiguration opens a path to deeper access. This skill covers systematic enumeration, privilege escalation, secret extraction, and cluster-wide compromise techniques. ## Quick Workflow 1. Determine your initial position: pod shell, stolen token, exposed API, or kubeconfig file. 2. Enumerate service account permissions, cluster roles, and accessible resources. 3. Identify escalation vectors: RBAC gaps, kubelet exposure, hostPath mounts, cloud metadata access. 4. Escalate privileges by chaining misconfigurations or abusing overprivileged service accounts. 5. Extract secrets, pivot to other namespaces, and target the control plane. 6. Leverage cloud metadata or etcd access for infrastructure-wide compromise. --- ## Phase 1: Initial Enumeration …
Read the whole file at its exact version.
How to install
mdr add snailsploit/claude-red/offensive-k8s-attacks@git:20260825.8cffe5dmdr add snailsploit/claude-red/offensive-k8s-attacks@sha256:04382cb9bfa12bf6Pin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.
[](https://markdownregistry.com/a/art_ygg6yf5gz73m6zmc)
1 badge views in 30 days
Versions
Audit of the latest version
- fail: No link to a raw IP address (matched: http://127.0.0.1:10255)
- pass: Frontmatter block present
- pass: Frontmatter declares a name
- pass: Frontmatter declares a description
- pass: Size between 200 bytes and 200 KB (27489 bytes)
- pass: No zero-width or bidi control characters
- pass: No instruction hidden inside an HTML comment
- pass: No link to an exfiltration or paste host
- pass: No credential-shaped string
- pass: No instruction to send local credentials anywhere
- pass: No text hidden with inline styles
- pass: No prompt-injection phrasing
- pass: No curl or wget piped into a shell
- pass: No recursive delete of root, home or parent
- pass: No instruction to read or print local credentials
- pass: No base64 blob over 200 characters
- pass: No script tag
Source
snailsploit/claude-red · 6,831 stars · license MIT · pushed 2026-09-19 · branch main
API
GET https://markdownregistry.com/api/v1/artifacts/art_ygg6yf5gz73m6zmc GET https://markdownregistry.com/api/v1/resolve?ref=snailsploit/claude-red/offensive-k8s-attacks GET https://markdownregistry.com/api/v1/blob/04382cb9bfa12bf6f62bc3b2b22baf01e30e66624979450016462b158a4270e0
Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.
More from snailsploit/claude-red
Every file in snailsploit/claude-red