{"repo":"crazygit/kube-audit-kit","free":true,"listed":false,"github":"https://github.com/crazygit/kube-audit-kit","clone":"git clone https://github.com/crazygit/kube-audit-kit.git","description":"A Claude Code Skill for non-intrusive security audits of Kubernetes clusters.","language":"Python","stars":29,"topics":["audit","claude-code","kubernetes","skills"],"license":null,"category":"deployment-docker-iac","readme_excerpt":"English 简体中文 Kube Audit Kit Kube Audit Kit is a Claude Code Skill for non-intrusive security audits of Kubernetes clusters. Kube Audit Kit exports all resources in a specified Context/Namespace, deeply sanitizes them, groups applications intelligently, and generates a comprehensive security audit report based on the following industry standards: - Pod Security Standards (PSS) - NSA Kubernetes Guidelines - CIS Kubernetes Benchmark --- Features - Non-intrusive : Only get/list operations, no changes to cluster state - Full coverage : Dynamically discovers all namespaced resource types, with a small exclude list for low-value resources (e.g., events, bindings) - Smart grouping : Associates application resources based on workload topology - Dual audit : Scripted static scan + AI expert deep analysis - Type safety : Full Python type annotations - Nice output : Rich-powered colored console output Security Coverage 🛡️ Pod Security (Based on PSS/NSA) Based on Pod Security Standards and NSA Kubernetes Guidelines Check Item Description :---------------- :-------------------------------------------- Privileged Mode Detect privileged: true Host Namespaces Detect hostNetwork , hostPID , hostIPC Capabilities Detect dangerous capabilities add/drop Security Context Detect runAsNonRoot , readOnlyRootFilesystem Resource Limits Detect CPU/memory requests and limits Health Checks Detect liveness/readiness/startup probes Image Safety Detect :latest tag usage 🔐 RBAC Audit Based on CIS Kubernetes ","default_branch":null,"files":null,"tree":[],"storefront":"/r/crazygit","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/crazygit/kube-audit-kit/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}