All categories
Security
Security audits, vulnerabilities, compliance, auth, secrets, and safe automation
- 29,001
- 1,209
Security grades appear on each card once the skill has been scanned. Newly imported skills may briefly show without a grade until the backfill job runs.
Open in full browserBrowse security skills
Showing 1,297–1,320 of 29,001 skills
- Linux Device Tree Board Integration ReviewUse when a task involves reviewing device-tree changes for a board and kernel release to define the target, lifecycle stage, controlling artifact, authoritative evidence, version or operating conditions, sensitivity, and approval boundary before applying the method. Separate observed facts from assumptions and model output. Verify the result with appropriate independent checks, preserve provenance, and report uncertainty and limitations. Do not perform production, financial, device-control, d...Votes: 0GitHub stars: 2
- Kubernetes Workload Identity Trust Boundary AuditUse when a task involves reviewing how a Kubernetes workload identity is trusted by an external service to record Kubernetes server and client versions, cluster distribution and provider, API versions, namespace and workload owner, data sensitivity, evidence requirements, and maintenance window. Check current Kubernetes and provider documentation, begin with read-only evidence, and validate changes in an approved environment. Do not modify production resources, credentials, or persistent data...Votes: 0GitHub stars: 2
- Kubernetes Vpa Eviction Mode Disruption Risk ReviewUse when a task involves assessing Pod disruption before enabling a VPA update mode that recreates workloads to record Kubernetes server and client versions, cluster distribution and provider, API versions, namespace and workload owner, data sensitivity, evidence requirements, and maintenance window. Check current Kubernetes and provider documentation, begin with read-only evidence, and validate changes in an approved environment. Do not modify production resources, credentials, or persistent...Votes: 0GitHub stars: 2
- Kubernetes Volume Snapshot Application Consistency ValidationUse when a task involves checking whether a storage snapshot captures a usable application recovery point to record Kubernetes server and client versions, cluster distribution and provider, API versions, namespace and workload owner, data sensitivity, evidence requirements, and maintenance window. Check current Kubernetes and provider documentation, begin with read-only evidence, and validate changes in an approved environment. Do not modify production resources, credentials, or persistent da...Votes: 0GitHub stars: 2
- Kubernetes Volume Multiattach Contention DiagnosisUse when a task involves diagnosing a Pod blocked because a volume is already attached or mounted elsewhere to record Kubernetes server and client versions, cluster distribution and provider, API versions, namespace and workload owner, data sensitivity, evidence requirements, and maintenance window. Check current Kubernetes and provider documentation, begin with read-only evidence, and validate changes in an approved environment. Do not modify production resources, credentials, or persistent ...Votes: 0GitHub stars: 2
- Kubernetes Unschedulable Pod Event Root Cause TriageUse when a task involves diagnosing why a pending Pod has no feasible node to record Kubernetes server and client versions, cluster distribution and provider, API versions, namespace and workload owner, data sensitivity, evidence requirements, and maintenance window. Check current Kubernetes and provider documentation, begin with read-only evidence, and validate changes in an approved environment. Do not modify production resources, credentials, or persistent data without explicit owner appro...Votes: 0GitHub stars: 2
- Kubernetes Stuck Finalizer Resource Recovery PlanUse when a task involves planning recovery when a custom or core resource remains terminating because a finalizer is not cleared to record Kubernetes server and client versions, cluster distribution and provider, API versions, namespace and workload owner, data sensitivity, evidence requirements, and maintenance window. Check current Kubernetes and provider documentation, begin with read-only evidence, and validate changes in an approved environment. Do not modify production resources, creden...Votes: 0GitHub stars: 2
- Kubernetes Storageclass Default Change Impact ReviewUse when a task involves assessing workloads affected by changing or removing a default StorageClass to record Kubernetes server and client versions, cluster distribution and provider, API versions, namespace and workload owner, data sensitivity, evidence requirements, and maintenance window. Check current Kubernetes and provider documentation, begin with read-only evidence, and validate changes in an approved environment. Do not modify production resources, credentials, or persistent data wi...Votes: 0GitHub stars: 2
- Kubernetes Statefulset Quorum Rollout ReadinessUse when a task involves checking whether a stateful application can preserve its own quorum during a StatefulSet update to record Kubernetes server and client versions, cluster distribution and provider, API versions, namespace and workload owner, data sensitivity, evidence requirements, and maintenance window. Check current Kubernetes and provider documentation, begin with read-only evidence, and validate changes in an approved environment. Do not modify production resources, credentials, o...Votes: 0GitHub stars: 2
- Kubernetes Statefulset Partitioned Canary PlanUse when a task involves planning a staged StatefulSet update using ordinal partitions and explicit observation gates to record Kubernetes server and client versions, cluster distribution and provider, API versions, namespace and workload owner, data sensitivity, evidence requirements, and maintenance window. Check current Kubernetes and provider documentation, begin with read-only evidence, and validate changes in an approved environment. Do not modify production resources, credentials, or p...Votes: 0GitHub stars: 2
- Kubernetes Stateful Volume Zone Placement ReviewUse when a task involves checking whether stateful Pods can be scheduled where their bound storage is accessible to record Kubernetes server and client versions, cluster distribution and provider, API versions, namespace and workload owner, data sensitivity, evidence requirements, and maintenance window. Check current Kubernetes and provider documentation, begin with read-only evidence, and validate changes in an approved environment. Do not modify production resources, credentials, or persis...Votes: 0GitHub stars: 2
- Kubernetes Serviceaccount Automount Scope ReviewUse when a task involves checking whether Pods receive API credentials they do not need to record Kubernetes server and client versions, cluster distribution and provider, API versions, namespace and workload owner, data sensitivity, evidence requirements, and maintenance window. Check current Kubernetes and provider documentation, begin with read-only evidence, and validate changes in an approved environment. Do not modify production resources, credentials, or persistent data without explici...Votes: 0GitHub stars: 2
- Kubernetes Service Endpoint Readiness Mismatch TriageUse when a task involves diagnosing a Service that routes to too few, stale, or unexpected backend endpoints to record Kubernetes server and client versions, cluster distribution and provider, API versions, namespace and workload owner, data sensitivity, evidence requirements, and maintenance window. Check current Kubernetes and provider documentation, begin with read-only evidence, and validate changes in an approved environment. Do not modify production resources, credentials, or persistent...Votes: 0GitHub stars: 2
- Kubernetes Secret At Rest Encryption VerificationUse when a task involves verifying encryption-at-rest configuration for Kubernetes Secret objects to record Kubernetes server and client versions, cluster distribution and provider, API versions, namespace and workload owner, data sensitivity, evidence requirements, and maintenance window. Check current Kubernetes and provider documentation, begin with read-only evidence, and validate changes in an approved environment. Do not modify production resources, credentials, or persistent data witho...Votes: 0GitHub stars: 2
- Kubernetes Rbac Wildcard Permission ReductionUse when a task involves identifying Kubernetes RBAC wildcard grants that create unnecessary current or future access to record Kubernetes server and client versions, cluster distribution and provider, API versions, namespace and workload owner, data sensitivity, evidence requirements, and maintenance window. Check current Kubernetes and provider documentation, begin with read-only evidence, and validate changes in an approved environment. Do not modify production resources, credentials, or p...Votes: 0GitHub stars: 2
- Kubernetes Pvc Restore Integrity RehearsalUse when a task involves rehearsing restoration of a persistent-volume claim from an approved snapshot or backup to record Kubernetes server and client versions, cluster distribution and provider, API versions, namespace and workload owner, data sensitivity, evidence requirements, and maintenance window. Check current Kubernetes and provider documentation, begin with read-only evidence, and validate changes in an approved environment. Do not modify production resources, credentials, or persis...Votes: 0GitHub stars: 2
- Kubernetes Pvc Pending Binding Root Cause TriageUse when a task involves diagnosing a PersistentVolumeClaim that remains unbound or prevents a Pod from scheduling to record Kubernetes server and client versions, cluster distribution and provider, API versions, namespace and workload owner, data sensitivity, evidence requirements, and maintenance window. Check current Kubernetes and provider documentation, begin with read-only evidence, and validate changes in an approved environment. Do not modify production resources, credentials, or pers...Votes: 0GitHub stars: 2
- Kubernetes Pvc Expansion Failure Recovery PlanUse when a task involves planning a safe response when a supported persistent-volume claim expansion stalls or fails to record Kubernetes server and client versions, cluster distribution and provider, API versions, namespace and workload owner, data sensitivity, evidence requirements, and maintenance window. Check current Kubernetes and provider documentation, begin with read-only evidence, and validate changes in an approved environment. Do not modify production resources, credentials, or pe...Votes: 0GitHub stars: 2
- Kubernetes Pv Reclaim Policy Data Retention CheckUse when a task involves verifying what happens to backing storage when a claim or workload is removed to record Kubernetes server and client versions, cluster distribution and provider, API versions, namespace and workload owner, data sensitivity, evidence requirements, and maintenance window. Check current Kubernetes and provider documentation, begin with read-only evidence, and validate changes in an approved environment. Do not modify production resources, credentials, or persistent data ...Votes: 0GitHub stars: 2
- Kubernetes Projected Token Audience Expiry ValidationUse when a task involves checking that projected workload identity tokens are scoped and expire as intended to record Kubernetes server and client versions, cluster distribution and provider, API versions, namespace and workload owner, data sensitivity, evidence requirements, and maintenance window. Check current Kubernetes and provider documentation, begin with read-only evidence, and validate changes in an approved environment. Do not modify production resources, credentials, or persistent ...Votes: 0GitHub stars: 2
- Kubernetes Prestop Hook Idempotency ReviewUse when a task involves reviewing whether a Pod preStop action is safe across retries, delayed shutdown, and partial failure to record Kubernetes server and client versions, cluster distribution and provider, API versions, namespace and workload owner, data sensitivity, evidence requirements, and maintenance window. Check current Kubernetes and provider documentation, begin with read-only evidence, and validate changes in an approved environment. Do not modify production resources, credentia...Votes: 0GitHub stars: 2
- Kubernetes Pod Topology Spread Failure Domain ReviewUse when a task involves reviewing how workload replicas are distributed across zones or other topology domains to record Kubernetes server and client versions, cluster distribution and provider, API versions, namespace and workload owner, data sensitivity, evidence requirements, and maintenance window. Check current Kubernetes and provider documentation, begin with read-only evidence, and validate changes in an approved environment. Do not modify production resources, credentials, or persist...Votes: 0GitHub stars: 2
- Kubernetes Pdb Drain Deadlock DiagnosisUse when a task involves diagnosing a node drain blocked by a PodDisruptionBudget or unhealthy selected Pods to record Kubernetes server and client versions, cluster distribution and provider, API versions, namespace and workload owner, data sensitivity, evidence requirements, and maintenance window. Check current Kubernetes and provider documentation, begin with read-only evidence, and validate changes in an approved environment. Do not modify production resources, credentials, or persistent...Votes: 0GitHub stars: 2
- Kubernetes Orphan Ownerreference InventoryUse when a task involves identifying objects whose owner references no longer resolve to a live controlling resource to record Kubernetes server and client versions, cluster distribution and provider, API versions, namespace and workload owner, data sensitivity, evidence requirements, and maintenance window. Check current Kubernetes and provider documentation, begin with read-only evidence, and validate changes in an approved environment. Do not modify production resources, credentials, or pe...Votes: 0GitHub stars: 2