From k8s-security
Review a Kubernetes cluster's security across control plane, RBAC, workload configuration, network policy, secrets, and admission control, mapped to the CIS Kubernetes Benchmark and the 4Cs model. Use for a comprehensive cluster security assessment of a cluster you're authorized to review.
How this skill is triggered — by the user, by Claude, or both
Slash command
/k8s-security:k8s-cluster-reviewThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
A cluster assessment across all major control areas, each with findings, severity,
A cluster assessment across all major control areas, each with findings, severity, and remediation, anchored to the CIS Kubernetes Benchmark.
reference.md for checks)cloud-security.)k8s-rbac-review.)k8s-workload-hardening.)kubectl/manifests/IaC). Note managed vs.
self-managed (who owns the control plane).reference.md; delegate RBAC and workload depth to the
companion skills.security-reporting:cvss) and rank.A cluster report grouped by area with a CIS-mapped findings table + ranked top
risks. Confirmed issues → security-reporting:finding.
Think in 4Cs (Cloud, Cluster, Container, Code): a hardened pod on a wide-open API server is still exposed. On managed clusters, confirm which controls the provider owns vs. you. Default-deny network policy and restricting privileged pods are the highest-leverage wins.
Provides CDSS development patterns for drug interaction checking, dose validation, clinical scoring (NEWS2, qSOFA), and alert classification integrated into EMR workflows.
npx claudepluginhub jassics/awesome-claude-security --plugin k8s-security