‹ The Index

K8S Security Baseline

skill

- Run a CIS-derived security audit of a MANAGED Kubernetes cluster (Lambda or similar), scoped by shared responsibility: filter out provider-owned control plane checks (CIS sections 1-3), execute the customer-side checklist from sections 4-5 — RBAC minimization, Pod Security Standards labels, default-deny NetworkPolicies, secrets handling, admission control — plus GPU-specific risks (privileged device-plugin DaemonSets, NVIDIA container toolkit CVEs), and output a findings table with severity and remediation. …

Works with: Claude Code (native)  ·  Cursor, Codex CLI (manual)
native: this artifact type is that client's own format

Category: Security — see all ranked ›

Install (Claude Code):

cp -r k8s-security-baseline ~/.claude/skills/

Security audit

Not scanned yet. We audit npm-published capabilities for known advisories, install-time scripts and permission surface; this one has no npm package we can resolve, or has not reached the queue.

Its own instructions

Its SKILL.md says when not to and covers setup.

Read from the capability’s own SKILL.md. This is not a grade and does not compare to the instruction-depth verdict on an MCP server — a skill has no tools to document, so that rubric does not apply to it.

You searched for one. Check the rest of your stack:

npx tashan-cli doctor

Reads the config already on your machine and names what is dead, deprecated or running code at install time. No account, nothing uploaded.

tashan Pro$6/mo

Pro adds the history to tashan doctor, so a run over your own config says which of yours gained an advisory, started running an install script, or lost its last maintainer — and what to move to.

Start a 7-day trial › Everything measured on this page stays free.

source ↗  ·  skill:Cloud-Byte-Consulting/k8s-security-baseline

Everything on this page is public evidence and free. What it cannot know is whether you run this — check your whole config, free, in the browser. tashan Pro adds the series behind each row and names a replacement for anything dying.

Already running this? Check your whole config — free, in your browser, nothing installed. Or npx tashan-cli doctor locally, which sends nothing at all.

Measured 2026-08-22  ·  scorer s5  ·  how  ·  something wrong here?