All categories
Security
Security audits, vulnerabilities, compliance, auth, secrets, and safe automation
- 29,001
- 1,209
Security grades appear on each card once the skill has been scanned. Newly imported skills may briefly show without a grade until the backfill job runs.
Open in full browserBrowse security skills
Showing 1,321–1,344 of 29,001 skills
- Kubernetes Operator Reconcile Health DiagnosticUse when a task involves diagnosing an operator that is slow, stuck, or repeatedly reconciling the same custom resource to record Kubernetes server and client versions, cluster distribution and provider, API versions, namespace and workload owner, data sensitivity, evidence requirements, and maintenance window. Check current Kubernetes and provider documentation, begin with read-only evidence, and validate changes in an approved environment. Do not modify production resources, credentials, or...Votes: 0GitHub stars: 2
- Kubernetes Node Drain Capacity PreflightUse when a task involves checking whether workloads can fit elsewhere before an authorized node drain to record Kubernetes server and client versions, cluster distribution and provider, API versions, namespace and workload owner, data sensitivity, evidence requirements, and maintenance window. Check current Kubernetes and provider documentation, begin with read-only evidence, and validate changes in an approved environment. Do not modify production resources, credentials, or persistent data w...Votes: 0GitHub stars: 2
- Kubernetes Namespace Termination Finalizer TriageUse when a task involves diagnosing a namespace that remains in Terminating state to record Kubernetes server and client versions, cluster distribution and provider, API versions, namespace and workload owner, data sensitivity, evidence requirements, and maintenance window. Check current Kubernetes and provider documentation, begin with read-only evidence, and validate changes in an approved environment. Do not modify production resources, credentials, or persistent data without explicit owne...Votes: 0GitHub stars: 2
- Kubernetes Namespace Rolebinding Expiry ReviewUse when a task involves reviewing namespace-scoped access grants for current ownership, least privilege, and human-enforced review dates to record Kubernetes server and client versions, cluster distribution and provider, API versions, namespace and workload owner, data sensitivity, evidence requirements, and maintenance window. Check current Kubernetes and provider documentation, begin with read-only evidence, and validate changes in an approved environment. Do not modify production resource...Votes: 0GitHub stars: 2
- Kubernetes Kubelet Api Authentication Reachability CheckUse when a task involves checking whether kubelet endpoints are restricted to authenticated and authorized callers to record Kubernetes server and client versions, cluster distribution and provider, API versions, namespace and workload owner, data sensitivity, evidence requirements, and maintenance window. Check current Kubernetes and provider documentation, begin with read-only evidence, and validate changes in an approved environment. Do not modify production resources, credentials, or pers...Votes: 0GitHub stars: 2
- Kubernetes Job Backoff Retry Budget ReviewUse when a task involves setting retry behavior for a Kubernetes Job whose task can fail transiently or permanently to record Kubernetes server and client versions, cluster distribution and provider, API versions, namespace and workload owner, data sensitivity, evidence requirements, and maintenance window. Check current Kubernetes and provider documentation, begin with read-only evidence, and validate changes in an approved environment. Do not modify production resources, credentials, or per...Votes: 0GitHub stars: 2
- Kubernetes Ingressclass Controller Ownership AuditUse when a task involves identifying which controller reconciles each IngressClass and its attached routes to record Kubernetes server and client versions, cluster distribution and provider, API versions, namespace and workload owner, data sensitivity, evidence requirements, and maintenance window. Check current Kubernetes and provider documentation, begin with read-only evidence, and validate changes in an approved environment. Do not modify production resources, credentials, or persistent d...Votes: 0GitHub stars: 2
- Kubernetes Image Registry Outage Cold Start ReadinessUse when a task involves assessing whether workloads can start or recover when an image registry is unavailable to record Kubernetes server and client versions, cluster distribution and provider, API versions, namespace and workload owner, data sensitivity, evidence requirements, and maintenance window. Check current Kubernetes and provider documentation, begin with read-only evidence, and validate changes in an approved environment. Do not modify production resources, credentials, or persist...Votes: 0GitHub stars: 2
- Kubernetes Image Pull Credential Namespace Scope AuditUse when a task involves reviewing which Pods and namespaces can use credentials to pull private images to record Kubernetes server and client versions, cluster distribution and provider, API versions, namespace and workload owner, data sensitivity, evidence requirements, and maintenance window. Check current Kubernetes and provider documentation, begin with read-only evidence, and validate changes in an approved environment. Do not modify production resources, credentials, or persistent data...Votes: 0GitHub stars: 2
- Kubernetes External Secret Provider Access BoundaryUse when a task involves checking which workloads can retrieve secrets through an external provider integration to record Kubernetes server and client versions, cluster distribution and provider, API versions, namespace and workload owner, data sensitivity, evidence requirements, and maintenance window. Check current Kubernetes and provider documentation, begin with read-only evidence, and validate changes in an approved environment. Do not modify production resources, credentials, or persist...Votes: 0GitHub stars: 2
- Kubernetes Extended Resource Quota Fairness AuditUse when a task involves reviewing namespace allocation and quotas for GPUs or other non-overcommittable resources to record Kubernetes server and client versions, cluster distribution and provider, API versions, namespace and workload owner, data sensitivity, evidence requirements, and maintenance window. Check current Kubernetes and provider documentation, begin with read-only evidence, and validate changes in an approved environment. Do not modify production resources, credentials, or pers...Votes: 0GitHub stars: 2
- Kubernetes Etcd Snapshot Restore RehearsalUse when a task involves rehearsing recovery of Kubernetes control-plane state from an authorized etcd snapshot to record Kubernetes server and client versions, cluster distribution and provider, API versions, namespace and workload owner, data sensitivity, evidence requirements, and maintenance window. Check current Kubernetes and provider documentation, begin with read-only evidence, and validate changes in an approved environment. Do not modify production resources, credentials, or persist...Votes: 0GitHub stars: 2
- Kubernetes Csi Driver Version Compatibility AuditUse when a task involves checking whether an installed CSI driver and sidecars support the cluster and storage features in use to record Kubernetes server and client versions, cluster distribution and provider, API versions, namespace and workload owner, data sensitivity, evidence requirements, and maintenance window. Check current Kubernetes and provider documentation, begin with read-only evidence, and validate changes in an approved environment. Do not modify production resources, credenti...Votes: 0GitHub stars: 2
- Kubernetes Cronjob Overlap Concurrency PolicyUse when a task involves choosing how scheduled Jobs behave when a prior run is still active or missed to record Kubernetes server and client versions, cluster distribution and provider, API versions, namespace and workload owner, data sensitivity, evidence requirements, and maintenance window. Check current Kubernetes and provider documentation, begin with read-only evidence, and validate changes in an approved environment. Do not modify production resources, credentials, or persistent data ...Votes: 0GitHub stars: 2
- Kubernetes Crd Validation Defaulting Contract CheckUse when a task involves verifying that a custom-resource schema rejects invalid inputs and preserves intended defaults to record Kubernetes server and client versions, cluster distribution and provider, API versions, namespace and workload owner, data sensitivity, evidence requirements, and maintenance window. Check current Kubernetes and provider documentation, begin with read-only evidence, and validate changes in an approved environment. Do not modify production resources, credentials, or...Votes: 0GitHub stars: 2
- Kubernetes Apiserver Public Exposure ReviewUse when a task involves assessing whether a Kubernetes API endpoint is reachable from unintended network locations to record Kubernetes server and client versions, cluster distribution and provider, API versions, namespace and workload owner, data sensitivity, evidence requirements, and maintenance window. Check current Kubernetes and provider documentation, begin with read-only evidence, and validate changes in an approved environment. Do not modify production resources, credentials, or per...Votes: 0GitHub stars: 2
- Kubernetes Api Audit Policy Coverage MapUse when a task involves checking whether audit rules record security-relevant Kubernetes API actions at an appropriate level to record Kubernetes server and client versions, cluster distribution and provider, API versions, namespace and workload owner, data sensitivity, evidence requirements, and maintenance window. Check current Kubernetes and provider documentation, begin with read-only evidence, and validate changes in an approved environment. Do not modify production resources, credentia...Votes: 0GitHub stars: 2
- Kubernetes Admission Webhook Failure Policy Resilience ReviewUse when a task involves assessing how API writes behave when an admission webhook is slow or unavailable to record Kubernetes server and client versions, cluster distribution and provider, API versions, namespace and workload owner, data sensitivity, evidence requirements, and maintenance window. Check current Kubernetes and provider documentation, begin with read-only evidence, and validate changes in an approved environment. Do not modify production resources, credentials, or persistent da...Votes: 0GitHub stars: 2
- Docker Sandbox Network And CredentialsUse when a task involves configuring network egress and service credentials for a Docker Sandbox with least privilege to identify the intended outcome, affected account or artifact, exact product version, sensitive data, and permission boundary before acting. Use current primary documentation for version-sensitive details, produce a reviewable result, and verify it against explicit criteria. Trigger for planning, configuration, implementation, or troubleshooting in this focused area; do not r...Votes: 0GitHub stars: 2
- Docker Compose Stack DesignUse when a task involves designing a local multi-container Compose stack with clear service boundaries, health checks, and safe data handling to identify the intended outcome, affected account or artifact, exact product version, sensitive data, and permission boundary before acting. Use current primary documentation for version-sensitive details, produce a reviewable result, and verify it against explicit criteria. Trigger for planning, configuration, implementation, or troubleshooting in thi...Votes: 0GitHub stars: 2
- Container Assurance Sbom Subject Approval Evidence PacketUse when a container SBOM subject binding result is ready for a human owner to approve, reject, or redirect to produce a decision packet for the SBOM-to-image binding record containing options, evidence, risks, and open questions. Success means the decision owner, requested decision, source evidence, alternatives, uncertainty, and consequence of no action are all visible; the SBOM subject matches the exact image digest and platform under review. Use configured search, fetch, read, browser, te...Votes: 0GitHub stars: 2
- Container Assurance Sandbox Egress Threshold Rule CheckUse when a container sandbox network egress decision depends on a limit, eligibility rule, policy, or target to produce a rule-check record for the sandbox egress evidence sheet showing source, units, boundary case, and outcome. Success means the rule source and effective date are verified, units and scope match, and borderline cases are flagged rather than auto-approved; only declared destinations are reachable in the test and credentials do not leak through denied paths. Use configured sear...Votes: 0GitHub stars: 2
- Container Assurance Sandbox Egress Source Provenance LedgerUse when a decision about container sandbox network egress depends on facts from several records or public sources to produce a source-to-claim provenance ledger for the sandbox egress evidence sheet. Success means each material claim has a source, version/date, location, and confidence note; only declared destinations are reachable in the test and credentials do not leak through denied paths. Use configured search, fetch, read, browser, test, and write capabilities only when relevant and aut...Votes: 0GitHub stars: 2
- Container Assurance Sandbox Egress Scope Intake GateUse when a new container sandbox network egress request needs a bounded work scope to produce a scoped intake card for the sandbox egress evidence sheet. Success means owner, objective, permitted sources, acceptance condition, exclusions, and deadline are explicit; only declared destinations are reachable in the test and credentials do not leak through denied paths. Use configured search, fetch, read, browser, test, and write capabilities only when relevant and authorized. Record evidence, li...Votes: 0GitHub stars: 2