What problem does it solve?
Existing security and compliance frameworks (including NIST 800-53, ISO 27001, and the CIS Kubernetes Benchmark) were designed for pre-2024 network-centric and early-cloud environments, with no coverage for mid-2026 threats like AI inference workload risks, kernel LPE-driven container escape, or MCP/agent tool trust boundaries, leaving teams unable to secure modern Kubernetes environments or meet evolving global regulatory requirements.
Core Features & Use Cases
- Framework Gap Mapping: Explicitly flags where 15+ global security and compliance frameworks fail to cover mid-2026 container and Kubernetes threat patterns, with per-control gap explanations.
- 6-Layer Defense-in-Depth Procedure: Step-by-step guidance for implementing image signing, admission control, Pod Security Standards, network policy, eBPF runtime detection, and control-plane hardening.
- AI Inference Workload Hardening: Dedicated guidance for securing KServe, vLLM, Triton Inference Server, and other AI workloads running on Kubernetes, including model serialization restrictions and GPU access controls.
- Exploit & TTP Reference: Includes exploit availability matrices, ATT&CK/ATLAS TTP mappings, and CWE cross-walks for common container/K8s attack vectors.
- Use Case: A financial services team running LLM inference on a self-managed Kubernetes cluster can use this skill to identify that NSA/CISA Kubernetes Hardening Guide v1.2 has no AI workload guidance, and implement the exact Kyverno and Sigstore policy steps to harden their inference pods against container escape and model exfiltration.
Quick Start
Use the container-runtime-security skill to audit your Kubernetes cluster's Pod Security Standards enforcement across all namespaces and generate a prioritized remediation plan for any non-compliant workloads.