Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add JustineDevs/premortem --skill container-securitygit clone --depth 1 https://github.com/JustineDevs/premortemWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/justinedevs/premortem/container-security)<a href="https://agentmods.dev/skills/justinedevs/premortem/container-security"><img src="https://agentmods.dev/badge/skills/justinedevs/premortem/container-security/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/justinedevs/premortem/container-security"><img src="https://agentmods.dev/badge/skills/justinedevs/premortem/container-security.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00118 | $0.02373 |
| Opus 5 | $0.00059 | $0.01187 |
| Sonnet 5 | $0.00024 | $0.00475 |
| Haiku 4.5 | $0.00012 | $0.00237 |
Grade A, and why
container-security scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
| Kubescape | K8s security platform | `curl -s https://raw.githubusercontent.com/kubescape/kubescape/master/install.sh \| /bin/bash` | This is a copy
92% identical to container-security — 10 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
How it starts
The opening of the file, as written. The whole thing — 196 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Container Security
Thin router for container and Kubernetes security assessments. Load the reference, workflow, or payload file you need — do not read all of them.
When to Use
- Scanning Docker/OCI images for CVEs (single image or pipeline)
- Generating or attesting SBOMs (Syft / CycloneDX / SPDX)
- Diffing SBOMs across releases to flag newly-introduced CVEs
- Auditing a live Kubernetes cluster (CIS / NSA / MITRE)
- Mapping K8s RBAC and finding privilege-escalation paths
- Reviewing NetworkPolicy coverage
- Authoring Falco / Tetragon runtime rules
- Analyzing or testing container escape vectors (authorized only)
- Docker daemon / host hardening review
Trigger Phrases
"scan this image", "trivy / grype / syft", "audit k8s cluster", "kube-bench", "kubescape", "run CIS benchmark", "check RBAC", "networkpolicy coverage", "falco rule", "container escape", "SBOM diff", "new CVEs since last release".
When NOT to Use This Skill
| Request | Use instead |
|---|---|
| Static scan of K8s YAML / Helm / Kustomize before deploy | iac-security |
| Terraform / CloudFormation / Pulumi misconfig | iac-security |
| EKS / GKE / AKS control-plane or managed-service misconfig | cloud-security |
| Cloud IAM misconfiguration (beyond K8s RBAC) | cloud-security |
| Application-code vulns inside the container | sast-orchestration |
| Third-party library CVEs at source-code level | sca-security |
| API endpoints exposed by containerized services | api-security |
Rule of thumb: pre-deployment YAML → iac-security; running cluster or built image → this skill.
Decision Tree
Target?
|
|-- Built/registry image ----------> workflows/image_scan.md
| \-- two images to compare? --> workflows/sbom_diff.md (FLAGSHIP)
|
|-- Dockerfile source -------------> examples/vulnerable_dockerfile.md
| + hadolint (references/image_scanning.md)
|
|-- Live K8s cluster --------------> workflows/cluster_audit.md
| |-- RBAC deep-dive ----------> workflows/rbac_analysis.md
| |-- Network policy gap ------> workflows/network_policy_review.md
| \-- CIS benchmark only ------> references/kubernetes_hardening.md
|
|-- Runtime monitoring ------------> references/runtime_security.md
| + examples/falco_custom_rule.yaml
|
\-- Escape testing (authorized) --> references/container_escape.md
+ payloads/container_escape_poc.md
What ships with it
15 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- examples/falco_custom_rule.yaml 3.5 KB
- examples/vulnerable_dockerfile.md 3.5 KB
- payloads/container_escape_poc.md 7.7 KB
- references/bounty_patterns_2024_2026.md 8.5 KB
- references/container_escape.md 5.3 KB
- references/image_scanning.md 3.8 KB
- references/kubernetes_hardening.md 5.2 KB
- references/runtime_security.md 4.3 KB
- schemas/finding.json 3.1 KB
- templates/assessment_report_template.md 2.0 KB
- workflows/cluster_audit.md 2.6 KB
- workflows/image_scan.md 2.0 KB
- workflows/network_policy_review.md 2.2 KB
- workflows/rbac_analysis.md 2.6 KB
- workflows/sbom_diff.md 4.2 KB
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 196 lines · 118 tokens per session scan A d4deb1dfae87
container-security is a skill published in the GitHub repository JustineDevs/premortem (2 stars, last pushed 1mo ago), licensed Apache-2.0. It adds 118 tokens to every session and 2,373 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). It is 92% identical to container-security, differing in 10 lines, and is treated as a copy.
Other skills, from other repositories
aws-cli
CLI-first AWS orchestration skill for Lambda, ECS/Fargate, and S3 workflows rooted in .☁️ runbooks.
azure-kubernetes-app-deploy
Use when deploying an existing web application or API to an already-running Azure Kubernetes Service cluster. Detects the framework, generates a Dockerfile and Kubernetes manifests, validates against AKS Deployment Safeguards, and deploys with verification. WHEN: deploy app to AKS, deploy to existing AKS cluster…
atmos-container
Atmos container components: components.container, Docker Compose migration, build/run/push/pull/up/down/list/ps/logs/exec, stack-scoped persistent containers, container workflow steps, compositions, and hooks.
atmos-emulator
Atmos emulator components: local AWS/GCP/Azure/Kubernetes/Vault/OpenBao/registry emulators, components.emulator, !emulator, identities, persistence, health checks, and emulator commands.
ak-cloud-deploy
Deploy an Agent Kernel project to AWS, Azure, or GCP using Terraform modules, or to any Kubernetes cluster (on-prem, baremetal, EKS) using the official Helm chart. Supports serverless and containerized modes for all three clouds. AWS supports execution modes (restsync, restasync, async, stream), queue-based scalable…
provisioning-infrastructure
Cloud-native infrastructure knowledge reference covering Kubernetes, Helm, Kustomize, Operators, CRDs, GitOps (ArgoCD, Flux), and IaC (Terraform, Pulumi, CDK). Use when provisioning infrastructure, managing clusters, or working with GitOps workflows.