SkillAgentSearch skills...

container-k8s-escape

Use when breaking out of a container or escalating inside Kubernetes β€” runc/BuildKit CVEs, privileged/capability/cgroup misconfig escapes, NVIDIA GPU toolkit escape, K8s RBAC abuse, kubelet RCE, ingress/admission-controller RCE, node-to-cluster pivot

Install / Use

npx skills add hypnguyen1209/offensive-claude --skill container-k8s-escape

Installs into whichever agent you are using.

About this skill
πŸ“„

SKILL.md

Installable skill definition

Quality Score

86/100

Category

Security

Supported Platforms

Universal

Our assessment of container-k8s-escape

container-k8s-escape scores 86/100 on our quality scale, 717th of 1,096 Security skills we index.

Its SKILL.md is 9.9 KB long, well organised into 12 sections with 1 code example: a thorough specification that gives an agent plenty to work with.

It has 377 GitHub stars, a meaningful sign that others use it.

Substance
29/30
Structure
17/20
Description
15/15
Adoption
11/20
Freshness
15/15

Maintenance, license and trust

  • The repository was last updated 14 days ago, so container-k8s-escape is actively maintained.
  • It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
  • Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit β€” read the skill file before letting an agent act on it.

Safety scan

No issues found

Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands.

Automated pattern scan on 2026-10-05. It catches known dangerous patterns, not every risk β€” read a skill before letting an agent act on it.

container-k8s-escape compared with similar skills

All 4 of these similar skills score higher than container-k8s-escape; compare them before choosing.

SkillScoreStarsUpdatedFormat
container-k8s-escape (this skill)by hypnguyen12098637714d agoSKILL.md
algorithmic-artby anthropics100177.9k12d agoSKILL.md
pptxby anthropics100177.9k12d agoSKILL.md
designby nextlevelbuilder100130.2k13d agoSKILL.md
ui-ux-pro-maxby nextlevelbuilder100130.2k13d agoSKILL.md

Frequently asked questions

How do I install container-k8s-escape?
Run npx skills add hypnguyen1209/offensive-claude --skill container-k8s-escape. The install tabs above show the steps for each supported agent.
Which AI agents does container-k8s-escape work with?
It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
Is container-k8s-escape safe to use?
Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is container-k8s-escape still maintained?
The repository was last updated 14 days ago, so container-k8s-escape is actively maintained.

name: container-k8s-escape description: Use when breaking out of a container or escalating inside Kubernetes β€” runc/BuildKit CVEs, privileged/capability/cgroup misconfig escapes, NVIDIA GPU toolkit escape, K8s RBAC abuse, kubelet RCE, ingress/admission-controller RCE, node-to-cluster pivot metadata: type: offensive phase: exploit-install-actions tools: kubectl, crictl, runc, deepce, cdk, kube-hunter, peirates, amicontained, trufflehog, falco, kubeletctl, nsenter mitre: [T1611, T1610, T1613, T1552.001, T1552.007, T1078.001, T1068, T1496] kill_chain: phase: [exploit, install, actions] step: [4, 5, 7] attck_tactics: [TA0002, TA0004, TA0005, TA0006, TA0008] attck_techniques: [T1611, T1610, T1613, T1609, T1552.001, T1552.007, T1078.001, T1068, T1496, T1610] depends_on: [recon-osint, cloud-security, vulnerability-analysis] feeds_into: [cloud-security, red-team-ops, privesc-linux, active-directory-attack] inputs: [container_context, k8s_service_account, kubeconfig, node_access, registry_push_access] outputs: [host_root_shell, node_compromise, stolen_sa_tokens, cluster_admin, attack_path, escape_finding] references:

  • references/runtime-cve-escapes.md
  • references/privileged-misconfig-escape.md
  • references/nvidia-gpu-escape.md
  • references/k8s-rbac-escalation.md
  • references/ingress-admission-attacks.md
  • references/node-host-pivot.md scripts:
  • scripts/escape_enum.sh
  • scripts/runc_cwd_escape.py
  • scripts/release_agent_escape.sh
  • scripts/nvidiascape_build.sh
  • scripts/k8s_rbac_audit.py
  • scripts/kubelet_exec.py

Container Breakout & Kubernetes Escape

When to Activate

  • You have code execution inside a container/pod and want to break out to the host node
  • Auditing a Kubernetes cluster for RBAC privilege-escalation and lateral-movement paths
  • Assessing runc/containerd/BuildKit/Docker runtime versions against known escape CVEs
  • A pod is privileged, has dangerous capabilities, hostPath/hostPID/hostNetwork, or a mounted docker.sock
  • Attacking GPU/AI workloads using the NVIDIA Container Toolkit
  • Testing ingress-nginx / admission-controller exposure for unauthenticated RCE
  • Post-escape: pivoting from one node to full cluster takeover (kubelet, SA tokens, etcd, cloud IMDS)
  • Building Falco/Sigma detections for container-escape behavior (defensive validation)

Technique Map

| Technique | ATT&CK | CWE | Reference | Script | |-----------|--------|-----|-----------|--------| | runc working-dir fd leak escape (Leaky Vessels, CVE-2024-21626) | T1611 | CWE-403 | references/runtime-cve-escapes.md | scripts/runc_cwd_escape.py | | runc masked-path / /dev/null symlink escape (CVE-2025-31133) | T1611 | CWE-367 | references/runtime-cve-escapes.md | scripts/runc_cwd_escape.py | | runc /dev/console bind-mount + LSM bypass (CVE-2025-52565/52881) | T1611 | CWE-363 | references/runtime-cve-escapes.md | scripts/escape_enum.sh | | BuildKit cache/teardown symlink escape (CVE-2024-23651/52/53) | T1611 | CWE-59 | references/runtime-cve-escapes.md | scripts/escape_enum.sh | | Privileged / CAP_SYS_ADMIN cgroup release_agent escape | T1611 | CWE-269 | references/privileged-misconfig-escape.md | scripts/release_agent_escape.sh | | core_pattern host-side code exec on crash | T1611 | CWE-269 | references/privileged-misconfig-escape.md | scripts/release_agent_escape.sh | | hostPID + nsenter into PID 1 namespace | T1611 | CWE-668 | references/privileged-misconfig-escape.md | scripts/escape_enum.sh | | Mounted docker.sock / containerd.sock host takeover | T1610 | CWE-668 | references/privileged-misconfig-escape.md | scripts/escape_enum.sh | | hostPath / mount β†’ write host filesystem | T1611 | CWE-22 | references/privileged-misconfig-escape.md | scripts/escape_enum.sh | | NVIDIAScape LD_PRELOAD OCI-hook escape (CVE-2025-23266) | T1611 | CWE-426 | references/nvidia-gpu-escape.md | scripts/nvidiascape_build.sh | | NVIDIA CT TOCTOU mount escape (CVE-2024-0132 / CVE-2025-23359) | T1611 | CWE-367 | references/nvidia-gpu-escape.md | scripts/nvidiascape_build.sh | | K8s RBAC privesc (verb/wildcard/escalate, SA token theft) | T1078.001 | CWE-269 | references/k8s-rbac-escalation.md | scripts/k8s_rbac_audit.py | | nodes/proxy GET β†’ kubelet WebSocket exec RCE | T1609 | CWE-863 | references/k8s-rbac-escalation.md | scripts/kubelet_exec.py | | Anonymous/authed kubelet API exec on :10250 | T1609 | CWE-306 | references/k8s-rbac-escalation.md | scripts/kubelet_exec.py | | IngressNightmare unauth RCE (CVE-2025-1974 + annotation chain) | T1190 | CWE-94 | references/ingress-admission-attacks.md | scripts/escape_enum.sh | | Node β†’ cluster pivot (etcd, IMDS, SA-token harvest) | T1613 | CWE-552 | references/node-host-pivot.md | scripts/escape_enum.sh |

Quick Start

# 0. Enumerate the container/pod context: caps, mounts, sockets, runtime versions, K8s creds
bash scripts/escape_enum.sh                 # run INSIDE the target container

# 1. Runtime-CVE path: detect vulnerable runc/BuildKit and run the cwd-fd escape (CVE-2024-21626)
python3 scripts/runc_cwd_escape.py --probe                       # try fd 7,8,9 -> host /
python3 scripts/runc_cwd_escape.py --cmd 'id; cat /etc/shadow'   # via docker -w or k8s revshell

# 2. Misconfig path: privileged / CAP_SYS_ADMIN -> cgroup release_agent host code exec
bash scripts/release_agent_escape.sh -c 'id > /tmp/escape_out'   # reads host PID list / runs cmd

# 3. GPU path: build a malicious image for NVIDIAScape (CVE-2025-23266)
bash scripts/nvidiascape_build.sh --cmd 'id; cat /etc/shadow' --tag evil-gpu:latest

# 4. K8s RBAC: audit who can escalate / reach the kubelet (needs a kubeconfig or in-pod SA token)
python3 scripts/k8s_rbac_audit.py --kubeconfig ~/.kube/config --dangerous

# 5. nodes/proxy or open kubelet -> exec into any pod on the node
python3 scripts/kubelet_exec.py --node 10.0.0.5 --pod kube-system/etcd-master \
        --container etcd --cmd 'cat /var/lib/etcd/...' --token "$SA_TOKEN"

Recommended tooling: deepce / cdk / amicontained (in-container recon), peirates (K8s pivot), kube-hunter (cluster scan), kubeletctl (kubelet API), crictl (post-escape node control), falco (defensive validation of every technique below).

OPSEC & Detection (summary)

| Technique | Telemetry / IOC | Detection (Sigma/EDR/Falco) | OPSEC note | |-----------|-----------------|------------------------------|------------| | runc cwd-fd escape (CVE-2024-21626) | container process cwd under /proc/self/fd/N; getcwd ENOENT errors; host-path access from pid1 | Falco Container Drift/unexpected host-fs read; alert on runtime < runc 1.1.12 | No new files needed; works via -w/cwd only β€” very quiet, but lands on real host fs | | runc 2025 trio (masked-path/console) | symlink swap of /dev/null or /dev/pts/N; RW open of /proc/sysrq-trigger/core_pattern | Falco "Write below /proc/sys"/sysrq; mount race anomalies | Symlink swap is a timing race; on failure may crash host (sysrq) β€” loud | | release_agent / core_pattern | mount of cgroup/cgroup2; write to */release_agent or /proc/sys/kernel/core_pattern | Falco Detect release_agent File Container Escapes; Sigma on write to core_pattern | Requires CAP_SYS_ADMIN+mount; release_agent is cgroup-v1 only | | nsenter / hostPID | nsenter --target 1; process entering host mount/pid ns | Falco "nsenter" / proc.name=nsenter in container; ATT&CK T1611 | hostPID is visible in pod spec; nsenter is a strong IOC | | docker.sock abuse | /var/run/docker.sock mounted; curl --unix-socket create privileged container | Falco "Docker socket access by unexpected proc"; new privileged container event | Spawns a new privileged container β€” visible to docker/containerd events | | NVIDIAScape (CVE-2025-23266) | image ENV LD_PRELOAD=/proc/self/cwd/*.so; nvidia hook loads .so from container fs | Falco shared-lib load by nvidia-ctk/hook from container path | Needs only image push + run; no kernel bug β€” image scan catches the ENV | | nodes/proxy β†’ kubelet exec | WebSocket GET to kubelet /exec//run on :10250; no API-server audit entry | Runtime/L7 only β€” invisible to API audit & GuardDuty; monitor kubelet access log | Bypasses API-server audit & admission entirely β€” extremely stealthy | | K8s RBAC privesc / SA-token theft | read of /var/run/secrets/.../token; can-i probes; bind to cluster-admin | API audit create rolebindings/escalate; Falco Read SA token | kubectl auth can-i probing is logged at API server | | IngressNightmare (CVE-2025-1974) | AdmissionReview with injected NGINX directive; .so loaded from /proc/<pid>/fd | Sysdig/Falco "IngressNightmare"; shared-lib load from /proc in nginx | Code runs during nginx -t validation; controller SA grabs all-namespace secrets |

Deep Dives

  • references/runtime-cve-escapes.md β€” runc CVE-2024-21626 (working-dir fd leak), the Nov-2025 runc trio (CVE-2025-31133/52565/52881 masked-path & /dev/console), and the BuildKit Leaky Vessels CVEs, with full PoCs and version matrices.
  • references/privileged-misconfig-escape.md β€” --privileged/capability escapes: cgroup-v1 release_agent, core_pattern, hostPID+nsenter, mounted docker/containerd sockets, and hostPath// mounts, with complete scripts.
  • references/nvidia-gpu-escape.md β€” NVIDIAScape (CVE-2025-23266 LD_PRELOAD OCI-hook) and the CVE-2024-0132 / CVE-2025-23359 TOCTOU mount escapes in the NVIDIA Container Toolkit; build-and-run PoCs.
  • references/k8s-rbac-escalation.md β€” RBAC privilege escalation (wildcards, escalate/bind, pods/exec, impersonation), SA-token harvest, the nodes/proxy GET β†’ kubelet WebSocket exec RCE, and open kubelet :10250.
  • references/ingress-admission-attacks.md β€” IngressNightmare (CVE-2025-1974 + the annotation-injection chain), admission-webhook abuse, and how a controller SA leads to cluster-wide secret theft.
  • references/node-host-pivot.md β€” post-escape playbook: from one node to the whole cluster β€” etcd looting, kubelet/crictl, SA-token mining across pods, cloud IMDS role theft, and the defensive counterweight.

Related Skills

View on GitHub
GitHub Stars377
CategorySecurity
Updated14d ago
Forks65

Languages

Python

Trust signals

100/100

From repository metadata: license, adoption, age and documentation. Not a code audit β€” see the Safety scan above for what the skill file itself contains.

No cautions
container-k8s-escape β€” Universal Skill: Install & Safety Check | SkillAgent