container-k8s-escape
Use when breaking out of a container or escalating inside Kubernetes β runc/BuildKit CVEs, privileged/capability/cgroup misconfig escapes, NVIDIA GPU toolkit escape, K8s RBAC abuse, kubelet RCE, ingress/admission-controller RCE, node-to-cluster pivot
Install / Use
npx skills add hypnguyen1209/offensive-claude --skill container-k8s-escapeInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
SecuritySupported Platforms
Tags
Our assessment of container-k8s-escape
container-k8s-escape scores 86/100 on our quality scale, 717th of 1,096 Security skills we index.
Its SKILL.md is 9.9 KB long, well organised into 12 sections with 1 code example: a thorough specification that gives an agent plenty to work with.
It has 377 GitHub stars, a meaningful sign that others use it.
Maintenance, license and trust
- The repository was last updated 14 days ago, so container-k8s-escape is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit β read the skill file before letting an agent act on it.
Safety scan
No issues foundOur scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands.
Automated pattern scan on 2026-10-05. It catches known dangerous patterns, not every risk β read a skill before letting an agent act on it.
container-k8s-escape compared with similar skills
All 4 of these similar skills score higher than container-k8s-escape; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| container-k8s-escape (this skill)by hypnguyen1209 | 86 | 377 | 14d ago | SKILL.md |
| algorithmic-artby anthropics | 100 | 177.9k | 12d ago | SKILL.md |
| pptxby anthropics | 100 | 177.9k | 12d ago | SKILL.md |
| designby nextlevelbuilder | 100 | 130.2k | 13d ago | SKILL.md |
| ui-ux-pro-maxby nextlevelbuilder | 100 | 130.2k | 13d ago | SKILL.md |
Frequently asked questions
- How do I install container-k8s-escape?
- Run
npx skills add hypnguyen1209/offensive-claude --skill container-k8s-escape. The install tabs above show the steps for each supported agent. - Which AI agents does container-k8s-escape work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is container-k8s-escape safe to use?
- Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is container-k8s-escape still maintained?
- The repository was last updated 14 days ago, so container-k8s-escape is actively maintained.
Skill content
View source on GitHubname: container-k8s-escape description: Use when breaking out of a container or escalating inside Kubernetes β runc/BuildKit CVEs, privileged/capability/cgroup misconfig escapes, NVIDIA GPU toolkit escape, K8s RBAC abuse, kubelet RCE, ingress/admission-controller RCE, node-to-cluster pivot metadata: type: offensive phase: exploit-install-actions tools: kubectl, crictl, runc, deepce, cdk, kube-hunter, peirates, amicontained, trufflehog, falco, kubeletctl, nsenter mitre: [T1611, T1610, T1613, T1552.001, T1552.007, T1078.001, T1068, T1496] kill_chain: phase: [exploit, install, actions] step: [4, 5, 7] attck_tactics: [TA0002, TA0004, TA0005, TA0006, TA0008] attck_techniques: [T1611, T1610, T1613, T1609, T1552.001, T1552.007, T1078.001, T1068, T1496, T1610] depends_on: [recon-osint, cloud-security, vulnerability-analysis] feeds_into: [cloud-security, red-team-ops, privesc-linux, active-directory-attack] inputs: [container_context, k8s_service_account, kubeconfig, node_access, registry_push_access] outputs: [host_root_shell, node_compromise, stolen_sa_tokens, cluster_admin, attack_path, escape_finding] references:
- references/runtime-cve-escapes.md
- references/privileged-misconfig-escape.md
- references/nvidia-gpu-escape.md
- references/k8s-rbac-escalation.md
- references/ingress-admission-attacks.md
- references/node-host-pivot.md scripts:
- scripts/escape_enum.sh
- scripts/runc_cwd_escape.py
- scripts/release_agent_escape.sh
- scripts/nvidiascape_build.sh
- scripts/k8s_rbac_audit.py
- scripts/kubelet_exec.py
Container Breakout & Kubernetes Escape
When to Activate
- You have code execution inside a container/pod and want to break out to the host node
- Auditing a Kubernetes cluster for RBAC privilege-escalation and lateral-movement paths
- Assessing runc/containerd/BuildKit/Docker runtime versions against known escape CVEs
- A pod is privileged, has dangerous capabilities, hostPath/hostPID/hostNetwork, or a mounted docker.sock
- Attacking GPU/AI workloads using the NVIDIA Container Toolkit
- Testing ingress-nginx / admission-controller exposure for unauthenticated RCE
- Post-escape: pivoting from one node to full cluster takeover (kubelet, SA tokens, etcd, cloud IMDS)
- Building Falco/Sigma detections for container-escape behavior (defensive validation)
Technique Map
| Technique | ATT&CK | CWE | Reference | Script |
|-----------|--------|-----|-----------|--------|
| runc working-dir fd leak escape (Leaky Vessels, CVE-2024-21626) | T1611 | CWE-403 | references/runtime-cve-escapes.md | scripts/runc_cwd_escape.py |
| runc masked-path / /dev/null symlink escape (CVE-2025-31133) | T1611 | CWE-367 | references/runtime-cve-escapes.md | scripts/runc_cwd_escape.py |
| runc /dev/console bind-mount + LSM bypass (CVE-2025-52565/52881) | T1611 | CWE-363 | references/runtime-cve-escapes.md | scripts/escape_enum.sh |
| BuildKit cache/teardown symlink escape (CVE-2024-23651/52/53) | T1611 | CWE-59 | references/runtime-cve-escapes.md | scripts/escape_enum.sh |
| Privileged / CAP_SYS_ADMIN cgroup release_agent escape | T1611 | CWE-269 | references/privileged-misconfig-escape.md | scripts/release_agent_escape.sh |
| core_pattern host-side code exec on crash | T1611 | CWE-269 | references/privileged-misconfig-escape.md | scripts/release_agent_escape.sh |
| hostPID + nsenter into PID 1 namespace | T1611 | CWE-668 | references/privileged-misconfig-escape.md | scripts/escape_enum.sh |
| Mounted docker.sock / containerd.sock host takeover | T1610 | CWE-668 | references/privileged-misconfig-escape.md | scripts/escape_enum.sh |
| hostPath / mount β write host filesystem | T1611 | CWE-22 | references/privileged-misconfig-escape.md | scripts/escape_enum.sh |
| NVIDIAScape LD_PRELOAD OCI-hook escape (CVE-2025-23266) | T1611 | CWE-426 | references/nvidia-gpu-escape.md | scripts/nvidiascape_build.sh |
| NVIDIA CT TOCTOU mount escape (CVE-2024-0132 / CVE-2025-23359) | T1611 | CWE-367 | references/nvidia-gpu-escape.md | scripts/nvidiascape_build.sh |
| K8s RBAC privesc (verb/wildcard/escalate, SA token theft) | T1078.001 | CWE-269 | references/k8s-rbac-escalation.md | scripts/k8s_rbac_audit.py |
| nodes/proxy GET β kubelet WebSocket exec RCE | T1609 | CWE-863 | references/k8s-rbac-escalation.md | scripts/kubelet_exec.py |
| Anonymous/authed kubelet API exec on :10250 | T1609 | CWE-306 | references/k8s-rbac-escalation.md | scripts/kubelet_exec.py |
| IngressNightmare unauth RCE (CVE-2025-1974 + annotation chain) | T1190 | CWE-94 | references/ingress-admission-attacks.md | scripts/escape_enum.sh |
| Node β cluster pivot (etcd, IMDS, SA-token harvest) | T1613 | CWE-552 | references/node-host-pivot.md | scripts/escape_enum.sh |
Quick Start
# 0. Enumerate the container/pod context: caps, mounts, sockets, runtime versions, K8s creds
bash scripts/escape_enum.sh # run INSIDE the target container
# 1. Runtime-CVE path: detect vulnerable runc/BuildKit and run the cwd-fd escape (CVE-2024-21626)
python3 scripts/runc_cwd_escape.py --probe # try fd 7,8,9 -> host /
python3 scripts/runc_cwd_escape.py --cmd 'id; cat /etc/shadow' # via docker -w or k8s revshell
# 2. Misconfig path: privileged / CAP_SYS_ADMIN -> cgroup release_agent host code exec
bash scripts/release_agent_escape.sh -c 'id > /tmp/escape_out' # reads host PID list / runs cmd
# 3. GPU path: build a malicious image for NVIDIAScape (CVE-2025-23266)
bash scripts/nvidiascape_build.sh --cmd 'id; cat /etc/shadow' --tag evil-gpu:latest
# 4. K8s RBAC: audit who can escalate / reach the kubelet (needs a kubeconfig or in-pod SA token)
python3 scripts/k8s_rbac_audit.py --kubeconfig ~/.kube/config --dangerous
# 5. nodes/proxy or open kubelet -> exec into any pod on the node
python3 scripts/kubelet_exec.py --node 10.0.0.5 --pod kube-system/etcd-master \
--container etcd --cmd 'cat /var/lib/etcd/...' --token "$SA_TOKEN"
Recommended tooling: deepce / cdk / amicontained (in-container recon), peirates (K8s pivot),
kube-hunter (cluster scan), kubeletctl (kubelet API), crictl (post-escape node control),
falco (defensive validation of every technique below).
OPSEC & Detection (summary)
| Technique | Telemetry / IOC | Detection (Sigma/EDR/Falco) | OPSEC note |
|-----------|-----------------|------------------------------|------------|
| runc cwd-fd escape (CVE-2024-21626) | container process cwd under /proc/self/fd/N; getcwd ENOENT errors; host-path access from pid1 | Falco Container Drift/unexpected host-fs read; alert on runtime < runc 1.1.12 | No new files needed; works via -w/cwd only β very quiet, but lands on real host fs |
| runc 2025 trio (masked-path/console) | symlink swap of /dev/null or /dev/pts/N; RW open of /proc/sysrq-trigger/core_pattern | Falco "Write below /proc/sys"/sysrq; mount race anomalies | Symlink swap is a timing race; on failure may crash host (sysrq) β loud |
| release_agent / core_pattern | mount of cgroup/cgroup2; write to */release_agent or /proc/sys/kernel/core_pattern | Falco Detect release_agent File Container Escapes; Sigma on write to core_pattern | Requires CAP_SYS_ADMIN+mount; release_agent is cgroup-v1 only |
| nsenter / hostPID | nsenter --target 1; process entering host mount/pid ns | Falco "nsenter" / proc.name=nsenter in container; ATT&CK T1611 | hostPID is visible in pod spec; nsenter is a strong IOC |
| docker.sock abuse | /var/run/docker.sock mounted; curl --unix-socket create privileged container | Falco "Docker socket access by unexpected proc"; new privileged container event | Spawns a new privileged container β visible to docker/containerd events |
| NVIDIAScape (CVE-2025-23266) | image ENV LD_PRELOAD=/proc/self/cwd/*.so; nvidia hook loads .so from container fs | Falco shared-lib load by nvidia-ctk/hook from container path | Needs only image push + run; no kernel bug β image scan catches the ENV |
| nodes/proxy β kubelet exec | WebSocket GET to kubelet /exec//run on :10250; no API-server audit entry | Runtime/L7 only β invisible to API audit & GuardDuty; monitor kubelet access log | Bypasses API-server audit & admission entirely β extremely stealthy |
| K8s RBAC privesc / SA-token theft | read of /var/run/secrets/.../token; can-i probes; bind to cluster-admin | API audit create rolebindings/escalate; Falco Read SA token | kubectl auth can-i probing is logged at API server |
| IngressNightmare (CVE-2025-1974) | AdmissionReview with injected NGINX directive; .so loaded from /proc/<pid>/fd | Sysdig/Falco "IngressNightmare"; shared-lib load from /proc in nginx | Code runs during nginx -t validation; controller SA grabs all-namespace secrets |
Deep Dives
- references/runtime-cve-escapes.md β runc CVE-2024-21626 (working-dir fd leak), the Nov-2025 runc trio (CVE-2025-31133/52565/52881 masked-path &
/dev/console), and the BuildKit Leaky Vessels CVEs, with full PoCs and version matrices. - references/privileged-misconfig-escape.md β
--privileged/capability escapes: cgroup-v1release_agent,core_pattern,hostPID+nsenter, mounted docker/containerd sockets, andhostPath//mounts, with complete scripts. - references/nvidia-gpu-escape.md β NVIDIAScape (CVE-2025-23266
LD_PRELOADOCI-hook) and the CVE-2024-0132 / CVE-2025-23359 TOCTOU mount escapes in the NVIDIA Container Toolkit; build-and-run PoCs. - references/k8s-rbac-escalation.md β RBAC privilege escalation (wildcards,
escalate/bind,pods/exec, impersonation), SA-token harvest, thenodes/proxyGET β kubelet WebSocket exec RCE, and open kubelet :10250. - references/ingress-admission-attacks.md β IngressNightmare (CVE-2025-1974 + the annotation-injection chain), admission-webhook abuse, and how a controller SA leads to cluster-wide secret theft.
- references/node-host-pivot.md β post-escape playbook: from one node to the whole cluster β etcd looting, kubelet/crictl, SA-token mining across pods, cloud IMDS role theft, and the defensive counterweight.
Related Skills
algorithmic-art
177.9kCreating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems.
pptx
177.9kUse this skill any time a .pptx or .potx file is involved in any way β as input, output, or both. This includes: creating slide decks, pitch decks, or presentations; reading, parsing, or extracting text from any .pptx or .potx file (even if the extracted content will be used elsewhere, like in an emβ¦
design
130.2kComprehensive design skill: brand identity, design tokens, UI styling, logo generation (55 styles, Gemini, Atlas Cloud, or MuAPI AI), corporate identity program (50 deliverables, CIP mockups), HTML presentations (Chart.js), banner design (22 styles, social/ads/web/print), icon design (15 styles, SVGβ¦
ui-ux-pro-max
130.2kUI/UX design intelligence for web, mobile, and desktop. This skill should be used when designing, building, reviewing, or fixing interfaces, including pages, components, design systems, accessibility, interaction, responsive layout, typography, color, charts, and stack-specific UI implementation.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit β see the Safety scan above for what the skill file itself contains.
