k8s-securitycontext

k8s-securitycontext is a skill for Claude Code from andypitcher/ponytail-sec. It costs 57 tokens per session (412 once invoked), scanned A, original, MIT.

A checker for Kubernetes security settings. Kubernetes is software that runs containerized applications, and these settings control what those containers are allowed to do.

In plain words
What is it for?
Use it to review Pods, Deployments, Jobs, Helm templates, and other Kubernetes manifests for non-root users, restricted privileges, dropped capabilities, secure profiles, and read-only filesystems.
Why use it?
It gives a strict pass-or-fail result for required security settings instead of leaving important protections to manual review.

Skill for Claude Code

Written for Claude Code: shipped in a Claude Code plugin.

Part of the ponytail-sec plugin — 4 skills shipped together

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/andypitcher/ponytail-sec/k8s-securitycontext
Any agent
npx skills add andypitcher/ponytail-sec --skill k8s-securitycontext
Clone the repo
git clone --depth 1 https://github.com/andypitcher/ponytail-sec

Made for: Claude Code.

Or install ponytail-sec, the plugin that ships this one along with the rest of its 4 skills.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for k8s-securitycontext

README.md
[![agentmods](https://agentmods.dev/badge/skills/andypitcher/ponytail-sec/k8s-securitycontext.svg)](https://agentmods.dev/skills/andypitcher/ponytail-sec/k8s-securitycontext)
Your own site
<a href="https://agentmods.dev/skills/andypitcher/ponytail-sec/k8s-securitycontext"><img src="https://agentmods.dev/badge/skills/andypitcher/ponytail-sec/k8s-securitycontext.svg" alt="Measured on agentmods" height="20"></a>
Per session 57 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 412 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00057 $0.00412
Opus 5 $0.00028 $0.00206
Sonnet 5 $0.00011 $0.00082
Haiku 4.5 $0.00006 $0.00041

Measured 6d ago against content hash 622222aff4cf, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-06, from the pricing page.

Security

Grade A, and why

k8s-securitycontext scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/k8s-securitycontext/SKILL.md · 52 lines

What it actually says

Ask once before enforcing:

Enforce k8s-securitycontext skill? (yes / no)

If no: stop.

If yes: inspect locally first. Do not web-search by default. Web-search only if Kubernetes securityContext semantics are missing or ambiguous, and prefer the official Kubernetes docs.

Contract

Return exactly one line:

  • OK
  • NOT_OK: RULE, RULE

No severity. No advisory text. No maybes. If a rule cannot be verified, it is not OK.

Rules

All rules are mandatory for every application container. Apply to init and ephemeral containers when present too.

  • SC_NON_ROOT — require runAsNonRoot: true and no explicit root user (runAsUser: 0 is not OK).
  • SC_NO_PRIV_ESC — require allowPrivilegeEscalation: false.
  • SC_DROP_CAPS — require capabilities.drop: ["ALL"]; adding capabilities is not OK unless the manifest proves the workload needs them.
  • SC_SEC_PROFILE — require seccompProfile.type: RuntimeDefault or a stricter local profile.
  • SC_READ_ONLY_FS — require readOnlyRootFilesystem: true.
  • SC_SELINUX_TYPE — when the workload targets an SELinux-enforcing node class, OpenShift, SELinux-labeled volumes, or policy says SELinux is required, require seLinuxOptions.type. Missing type is not OK.

Output examples

OK

NOT_OK: SC_NON_ROOT, SC_NO_PRIV_ESC, SC_SELINUX_TYPE

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 6d ago First seen · 52 lines · 57 tokens per session scan A 622222aff4cf

Subscribe to this mod's changes

k8s-securitycontext is a skill published in the GitHub repository andypitcher/ponytail-sec (8 stars, last pushed 5d ago), licensed MIT. It adds 57 tokens to every session and 412 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

prowler-compliance

Creates, syncs, audits and manages Prowler compliance frameworks end-to-end. Covers the two supported JSON schemas (universal multi-provider and legacy per-provider), the SDK model tree (legacy attribute classes, universal ComplianceFramework, ConfigRequirements guardrails), output formatters (legacy per-framework +…

prowler-cloud/prowler · 227 tokens

prowler-attack-paths-query

Creates Prowler Attack Paths openCypher queries using the Cartography schema as the source of truth for node labels, properties, and relationships. Covers Prowler-specific additions (Internet node, ProwlerFinding, internal isolation labels), $provideruid scoping, and list-property item nodes with typed HAS edges that…

prowler-cloud/prowler · 97 tokens

django-migration-psql

Reviews Django migration files for PostgreSQL best practices specific to Prowler. Trigger: When creating migrations, running makemigrations/pgmakemigrations, reviewing migration PRs, adding indexes or constraints to database tables, modifying existing migration files, or writing data backfill migrations. Always use…

prowler-cloud/prowler · 96 tokens

framework-compliance-triage

Make a cloud account compliant with a security or industry framework using Prowler Cloud.

prowler-cloud/prowler · 24 tokens

postgresql-indexing

PostgreSQL indexing best practices for Prowler: index design, partial indexes, partitioned table indexing, EXPLAIN ANALYZE validation, concurrent operations, monitoring, and maintenance. Trigger: When creating or modifying PostgreSQL indexes, analyzing query performance with EXPLAIN, debugging slow queries, reviewing…

prowler-cloud/prowler · 108 tokens

gh-aw

Create and maintain GitHub Agentic Workflows (gh-aw) for Prowler. Trigger: When creating agentic workflows, modifying gh-aw frontmatter, configuring safe-outputs, setting up MCP servers in workflows, importing Copilot Custom Agents, or debugging gh-aw compilation.

prowler-cloud/prowler · 59 tokens