Securing managed Kubernetes on cloud - **name_fr:** Sécurisation de Kubernetes managé sur le cloud - **tl_en:** Harden EKS/AKS/GKE clusters — Pod Security Standards, workload identity, network policies, runtime monitoring - **tl_fr:** Durcir les clusters EKS/AKS/GKE — Pod Security Standards, workload identity, network policies, monitoring runtime - **creator:** @mukul975 - **type:** Agent skill - **url:** https://github.com/mukul975/anthropic-cybersecurity-skills - **cat:** Security - **kws:** kubernetes, eks, aks, gke, pod security, workload identity, network policies, containers - **license:** Apache-2.0 **Description EN:** Curated by Skill Harbor — a skill for hardening managed Kubernetes clusters on EKS, AKS and GKE: Pod Security Standards, network policies, workload identity (IRSA for EKS, Workload Identity for GKE, Managed Identities for AKS) to eliminate static cloud credentials in pods, RBAC scoping, image admission controls, and runtime security monitoring. Use when deploying a new managed cluster with security requirements, or hardening an existing one after an audit or pentest finding. By @mukul975, listed here with credit to its creator. Honest caveats: managed clusters only — self-hosted Kubernetes has different hardening paths; it needs admin access to the cluster and your cloud account, and admission controls can block legitimate workloads that aren't yet compliant, so enforce gradually. Not verified. Skill Harbor never reviews the code, review it yourself before use. Discovered via skills.sh. **Description FR:** Sélectionné par Skill Harbor — un skill pour durcir les clusters Kubernetes managés sur EKS, AKS et GKE : Pod Security Standards, network policies, workload identity (IRSA pour EKS, Workload Identity pour GKE, Managed Identities pour AKS) pour éliminer les identifiants cloud statiques dans les pods, périmètre RBAC, contrôles d'admission d'images et monitoring de sécurité runtime. À utiliser pour déployer un nouveau cluster managé avec des exigences de sécurité, ou durcir un cluster existant après un constat d'audit ou de pentest. Crédit : @mukul975. Bémols honnêtes : clusters managés uniquement — le Kubernetes auto-hébergé a d'autres chemins de durcissement ; il faut un accès admin au cluster et à votre compte cloud, et les contrôles d'admission peuvent bloquer des charges légitimes pas encore conformes, appliquez progressivement. Non vérifié. Skill Harbor ne vérifie jamais le code, examinez-le vous-même avant usage. Découvert via skills.sh. **Install prompt EN:** ``` Prerequisites: admin access to a managed Kubernetes cluster (EKS, AKS, or GKE) and your cloud account; kubectl configured against the cluster Install "Securing managed Kubernetes on cloud" for me. Give my agent the skill for hardening EKS/AKS/GKE clusters — Pod Security Standards, network policies, workload identity, RBAC scoping, admission controls, runtime monitoring Repository: https://github.com/mukul975/anthropic-cybersecurity-skills/blob/main/skills/securing-kubernetes-on-cloud/SKILL.md 1. Fetch the SKILL.md file for the mukul975-anthropic-cybersecurity-skills-securing-kubernetes-on-cloud skill from the repository into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md and scripts for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code, credentials only via the secure vault, allowed hosts declared in the SKILL.md. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md and its helper files into the agent's skills directory, in a folder named "mukul975-anthropic-cybersecurity-skills-securing-kubernetes-on-cloud". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. confirm cluster and cloud access, run an initial audit pass). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. Never ask me to paste secrets in chat — credentials go through the secure vault or environment variables. If anything looks off, stop and ask me. ``` **Install prompt FR:** ``` Prérequis : accès admin à un cluster Kubernetes managé (EKS, AKS ou GKE) et à votre compte cloud ; kubectl configuré contre le cluster Installe-moi « Sécurisation de Kubernetes managé sur le cloud ». Donne à mon agent le skill de durcissement des clusters EKS/AKS/GKE — Pod Security Standards, network policies, workload identity, périmètre RBAC, contrôles d'admission, monitoring runtime Dépôt : https://github.com/mukul975/anthropic-cybersecurity-skills/blob/main/skills/securing-kubernetes-on-cloud/SKILL.md 1. Récupère le fichier SKILL.md du skill mukul975-anthropic-cybersecurity-skills-securing-kubernetes-on-cloud depuis le dépôt dans un dossier temporaire et résume en une ou deux phrases ce qu'il fait. 2. Contrôle de sécurité : examine le SKILL.md et les scripts pour tout contenu suspect (appels réseau inattendus, commandes shell, récolte d'identifiants). Ce dépôt ne doit contenir aucun secret dans le code ; les identifiants passent uniquement par le coffre sécurisé, les hôtes autorisés sont déclarés dans le SKILL.md. Vérifie que c'est bien le cas ; STOP sur le moindre signal d'alerte et préviens-moi. 3. Installe-le comme skill : copie SKILL.md et ses fichiers auxiliaires dans le répertoire des skills de l'agent, dans un dossier nommé « mukul975-anthropic-cybersecurity-skills-securing-kubernetes-on-cloud ». 4. Vérifie sans aucun appel réseau : frontmatter valide, fichiers en place. 5. Indique ce qui a été installé, où, et ce qu'il me reste à faire moi-même (p. ex. confirmer l'accès au cluster et au cloud, lancer une première passe d'audit). GitHub est optionnel : si j'ai un compte GitHub ou la CLI gh, tu peux l'utiliser ; sinon l'accès public suffit. Ne jamais l'exiger sauf si c'est dans les prérequis ci-dessus. Règles : ne touche à rien en dehors du dossier temporaire et de la cible d'installation. Ne me demande jamais de coller des secrets dans le chat — les identifiants passent par le coffre sécurisé ou les variables d'environnement. Si quelque chose semble anormal, arrête-toi et demande-moi. ``` ---
Harden EKS/AKS/GKE clusters — Pod Security Standards, workload identity, network policies, runtime monitoring - **tl_fr:** Durcir les clusters EKS/AKS/GKE — Pod Security Standards, workload identity, network policies, monitoring runtime - **creator:** @mukul975 - **type:** Agent skill - **url:** https://github.com/mukul975/anthropic-cybersecurity-skills - **cat:** Security - **kws:** kubernetes, eks, aks, gke, pod security, workload identity, network policies, containers - **license:** Apache-2.0 **Description EN:** Curated by Skill Harbor — a skill for hardening managed Kubernetes clusters on EKS, AKS and GKE: Pod Security Standards, network policies, workload identity (IRSA for EKS, Workload Identity for GKE, Managed Identities for AKS) to eliminate static cloud credentials in pods, RBAC scoping, image admission controls, and runtime security monitoring. Use when deploying a new managed cluster with security requirements, or hardening an existing one after an audit or pentest finding. By @mukul975, listed here with credit to its creator. Honest caveats: managed clusters only — self-hosted Kubernetes has different hardening paths; it needs admin access to the cluster and your cloud account, and admission controls can block legitimate workloads that aren't yet compliant, so enforce gradually. Not verified. Skill Harbor never reviews the code, review it yourself before use. Discovered via skills.sh. **Description FR:** Sélectionné par Skill Harbor — un skill pour durcir les clusters Kubernetes managés sur EKS, AKS et GKE : Pod Security Standards, network policies, workload identity (IRSA pour EKS, Workload Identity pour GKE, Managed Identities pour AKS) pour éliminer les identifiants cloud statiques dans les pods, périmètre RBAC, contrôles d'admission d'images et monitoring de sécurité runtime. À utiliser pour déployer un nouveau cluster managé avec des exigences de sécurité, ou durcir un cluster existant après un constat d'audit ou de pentest. Crédit : @mukul975. Bémols honnêtes : clusters managés uniquement — le Kubernetes auto-hébergé a d'autres chemins de durcissement ; il faut un accès admin au cluster et à votre compte cloud, et les contrôles d'admission peuvent bloquer des charges légitimes pas encore conformes, appliquez progressivement. Non vérifié. Skill Harbor ne vérifie jamais le code, examinez-le vous-même avant usage. Découvert via skills.sh. **Install prompt EN:** ``` Prerequisites: admin access to a managed Kubernetes cluster (EKS, AKS, or GKE) and your cloud account; kubectl configured against the cluster Install "Securing managed Kubernetes on cloud" for me. Give my agent the skill for hardening EKS/AKS/GKE clusters — Pod Security Standards, network policies, workload identity, RBAC scoping, admission controls, runtime monitoring Repository: https://github.com/mukul975/anthropic-cybersecurity-skills/blob/main/skills/securing-kubernetes-on-cloud/SKILL.md 1. Fetch the SKILL.md file for the mukul975-anthropic-cybersecurity-skills-securing-kubernetes-on-cloud skill from the repository into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md and scripts for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code, credentials only via the secure vault, allowed hosts declared in the SKILL.md. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md and its helper files into the agent's skills directory, in a folder named "mukul975-anthropic-cybersecurity-skills-securing-kubernetes-on-cloud". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. confirm cluster and cloud access, run an initial audit pass). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. Never ask me to paste secrets in chat — credentials go through the secure vault or environment variables. If anything looks off, stop and ask me. ``` **Install prompt FR:** ``` Prérequis : accès admin à un cluster Kubernetes managé (EKS, AKS ou GKE) et à votre compte cloud ; kubectl configuré contre le cluster Installe-moi « Sécurisation de Kubernetes managé sur le cloud ». Donne à mon agent le skill de durcissement des clusters EKS/AKS/GKE — Pod Security Standards, network policies, workload identity, périmètre RBAC, contrôles d'admission, monitoring runtime Dépôt : https://github.com/mukul975/anthropic-cybersecurity-skills/blob/main/skills/securing-kubernetes-on-cloud/SKILL.md 1. Récupère le fichier SKILL.md du skill mukul975-anthropic-cybersecurity-skills-securing-kubernetes-on-cloud depuis le dépôt dans un dossier temporaire et résume en une ou deux phrases ce qu'il fait. 2. Contrôle de sécurité : examine le SKILL.md et les scripts pour tout contenu suspect (appels réseau inattendus, commandes shell, récolte d'identifiants). Ce dépôt ne doit contenir aucun secret dans le code ; les identifiants passent uniquement par le coffre sécurisé, les hôtes autorisés sont déclarés dans le SKILL.md. Vérifie que c'est bien le cas ; STOP sur le moindre signal d'alerte et préviens-moi. 3. Installe-le comme skill : copie SKILL.md et ses fichiers auxiliaires dans le répertoire des skills de l'agent, dans un dossier nommé « mukul975-anthropic-cybersecurity-skills-securing-kubernetes-on-cloud ». 4. Vérifie sans aucun appel réseau : frontmatter valide, fichiers en place. 5. Indique ce qui a été installé, où, et ce qu'il me reste à faire moi-même (p. ex. confirmer l'accès au cluster et au cloud, lancer une première passe d'audit). GitHub est optionnel : si j'ai un compte GitHub ou la CLI gh, tu peux l'utiliser ; sinon l'accès public suffit. Ne jamais l'exiger sauf si c'est dans les prérequis ci-dessus. Règles : ne touche à rien en dehors du dossier temporaire et de la cible d'installation. Ne me demande jamais de coller des secrets dans le chat — les identifiants passent par le coffre sécurisé ou les variables d'environnement. Si quelque chose semble anormal, arrête-toi et demande-moi. ``` ---
- What
- Harden EKS/AKS/GKE clusters — Pod Security Standards, workload identity, network policies, runtime monitoring - **tl_fr:** Durcir les clusters EKS/AKS/GKE — Pod Security Standards, workload identity, network policies, monitoring runtime - **creator:** @mukul975 - **type:** Agent skill - **url:** https://github.com/mukul975/anthropic-cybersecurity-skills - **cat:** Security - **kws:** kubernetes, eks, aks, gke, pod security, workload identity, network policies, containers - **license:** Apache-2.0 **Description EN:** Curated by Skill Harbor — a skill for hardening managed Kubernetes clusters on EKS, AKS and GKE: Pod Security Standards, network policies, workload identity (IRSA for EKS, Workload Identity for GKE, Managed Identities for AKS) to eliminate static cloud credentials in pods, RBAC scoping, image admission controls, and runtime security monitoring. Use when deploying a new managed cluster with security requirements, or hardening an existing one after an audit or pentest finding. By @mukul975, listed here with credit to its creator. Honest caveats: managed clusters only — self-hosted Kubernetes has different hardening paths; it needs admin access to the cluster and your cloud account, and admission controls can block legitimate workloads that aren't yet compliant, so enforce gradually. Not verified. Skill Harbor never reviews the code, review it yourself before use. Discovered via skills.sh. **Description FR:** Sélectionné par Skill Harbor — un skill pour durcir les clusters Kubernetes managés sur EKS, AKS et GKE : Pod Security Standards, network policies, workload identity (IRSA pour EKS, Workload Identity pour GKE, Managed Identities pour AKS) pour éliminer les identifiants cloud statiques dans les pods, périmètre RBAC, contrôles d'admission d'images et monitoring de sécurité runtime. À utiliser pour déployer un nouveau cluster managé avec des exigences de sécurité, ou durcir un cluster existant après un constat d'audit ou de pentest. Crédit : @mukul975. Bémols honnêtes : clusters managés uniquement — le Kubernetes auto-hébergé a d'autres chemins de durcissement ; il faut un accès admin au cluster et à votre compte cloud, et les contrôles d'admission peuvent bloquer des charges légitimes pas encore conformes, appliquez progressivement. Non vérifié. Skill Harbor ne vérifie jamais le code, examinez-le vous-même avant usage. Découvert via skills.sh. **Install prompt EN:** ``` Prerequisites: admin access to a managed Kubernetes cluster (EKS, AKS, or GKE) and your cloud account; kubectl configured against the cluster Install "Securing managed Kubernetes on cloud" for me. Give my agent the skill for hardening EKS/AKS/GKE clusters — Pod Security Standards, network policies, workload identity, RBAC scoping, admission controls, runtime monitoring Repository: https://github.com/mukul975/anthropic-cybersecurity-skills/blob/main/skills/securing-kubernetes-on-cloud/SKILL.md 1. Fetch the SKILL.md file for the mukul975-anthropic-cybersecurity-skills-securing-kubernetes-on-cloud skill from the repository into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md and scripts for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code, credentials only via the secure vault, allowed hosts declared in the SKILL.md. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md and its helper files into the agent's skills directory, in a folder named "mukul975-anthropic-cybersecurity-skills-securing-kubernetes-on-cloud". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. confirm cluster and cloud access, run an initial audit pass). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. Never ask me to paste secrets in chat — credentials go through the secure vault or environment variables. If anything looks off, stop and ask me. ``` **Install prompt FR:** ``` Prérequis : accès admin à un cluster Kubernetes managé (EKS, AKS ou GKE) et à votre compte cloud ; kubectl configuré contre le cluster Installe-moi « Sécurisation de Kubernetes managé sur le cloud ». Donne à mon agent le skill de durcissement des clusters EKS/AKS/GKE — Pod Security Standards, network policies, workload identity, périmètre RBAC, contrôles d'admission, monitoring runtime Dépôt : https://github.com/mukul975/anthropic-cybersecurity-skills/blob/main/skills/securing-kubernetes-on-cloud/SKILL.md 1. Récupère le fichier SKILL.md du skill mukul975-anthropic-cybersecurity-skills-securing-kubernetes-on-cloud depuis le dépôt dans un dossier temporaire et résume en une ou deux phrases ce qu'il fait. 2. Contrôle de sécurité : examine le SKILL.md et les scripts pour tout contenu suspect (appels réseau inattendus, commandes shell, récolte d'identifiants). Ce dépôt ne doit contenir aucun secret dans le code ; les identifiants passent uniquement par le coffre sécurisé, les hôtes autorisés sont déclarés dans le SKILL.md. Vérifie que c'est bien le cas ; STOP sur le moindre signal d'alerte et préviens-moi. 3. Installe-le comme skill : copie SKILL.md et ses fichiers auxiliaires dans le répertoire des skills de l'agent, dans un dossier nommé « mukul975-anthropic-cybersecurity-skills-securing-kubernetes-on-cloud ». 4. Vérifie sans aucun appel réseau : frontmatter valide, fichiers en place. 5. Indique ce qui a été installé, où, et ce qu'il me reste à faire moi-même (p. ex. confirmer l'accès au cluster et au cloud, lancer une première passe d'audit). GitHub est optionnel : si j'ai un compte GitHub ou la CLI gh, tu peux l'utiliser ; sinon l'accès public suffit. Ne jamais l'exiger sauf si c'est dans les prérequis ci-dessus. Règles : ne touche à rien en dehors du dossier temporaire et de la cible d'installation. Ne me demande jamais de coller des secrets dans le chat — les identifiants passent par le coffre sécurisé ou les variables d'environnement. Si quelque chose semble anormal, arrête-toi et demande-moi. ``` ---
- Cost
- Free
- Needs
- admin access to a managed Kubernetes cluster (EKS, AKS, or GKE) and your cloud account; kubectl configured against the cluster
- Install
- Copy the installer prompt below into your Muse — your agent does the rest.
Curated by Skill Harbor — a skill for hardening managed Kubernetes clusters on EKS, AKS and GKE: Pod Security Standards, network policies, workload identity (IRSA for EKS, Workload Identity for GKE, Managed Identities for AKS) to eliminate static cloud credentials in pods, RBAC scoping, image admission controls, and runtime security monitoring. Use when deploying a new managed cluster with security requirements, or hardening an existing one after an audit or pentest finding. By @mukul975, listed here with credit to its creator. Honest caveats: managed clusters only — self-hosted Kubernetes has different hardening paths; it needs admin access to the cluster and your cloud account, and admission controls can block legitimate workloads that aren't yet compliant, so enforce gradually. Not verified. Skill Harbor never reviews the code, review it yourself before use. Discovered via skills.sh.
Version:
Install
Prerequisites: admin access to a managed Kubernetes cluster (EKS, AKS, or GKE) and your cloud account; kubectl configured against the cluster Install "Securing managed Kubernetes on cloud" for me. Give my agent the skill for hardening EKS/AKS/GKE clusters — Pod Security Standards, network policies, workload identity, RBAC scoping, admission controls, runtime monitoring Repository: https://github.com/mukul975/anthropic-cybersecurity-skills/blob/main/skills/securing-kubernetes-on-cloud/SKILL.md 1. Fetch the SKILL.md file for the mukul975-anthropic-cybersecurity-skills-securing-kubernetes-on-cloud skill from the repository into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md and scripts for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code, credentials only via the secure vault, allowed hosts declared in the SKILL.md. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md and its helper files into the agent's skills directory, in a folder named "mukul975-anthropic-cybersecurity-skills-securing-kubernetes-on-cloud". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. confirm cluster and cloud access, run an initial audit pass). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. Never ask me to paste secrets in chat — credentials go through the secure vault or environment variables. If anything looks off, stop and ask me.
Questions
How do I install a build?
Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.
Where does my money go?
Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.
What does the ✓ next to a creator’s name mean?
It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.