← ClaudeAtlas

competition-kernel-container-escapelisted

Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for kernel attack surface, namespace and cgroup boundaries, container isolation assumptions, syscall paths, and escape primitive verification. Use when the user asks to analyze container-to-host escape paths, kernel exploit prerequisites, namespace crossover, capability misuse, or prove whether an exploit primitive crosses the sandbox boundary. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here.
xAmirHamza77/ReverseOps-Skill · ★ 4 · AI & Automation · score 72
Install: claude install-skill xAmirHamza77/ReverseOps-Skill
# Competition Kernel Container Escape Use this skill only as a downstream specialization after `$ctf-sandbox-orchestrator` is already active and has established sandbox assumptions, node ownership, and evidence priorities. If that has not happened yet, return to `$ctf-sandbox-orchestrator` first. Use this skill when the decisive step is proving a boundary crossing between containerized context and host or higher-privilege kernel context. Reply in Simplified Chinese unless the user explicitly requests English. ## Quick Start 1. Map runtime isolation first: namespaces, cgroups, seccomp, capabilities, LSM, and mount boundaries. 2. Separate exploit prerequisite, primitive, and boundary-crossing proof. 3. Record kernel version, config hints, runtime options, and reachable syscall surface. 4. Keep instrumented observations separate from pristine challenge path. 5. Reproduce one minimal primitive-to-boundary-crossing chain. ## Workflow ### 1. Map Isolation And Kernel Surface - Record namespace map, cgroup mode, capabilities, seccomp profile, AppArmor or SELinux state, mounted filesystems, and runtime sockets. - Note kernel version, distro build hints, module exposure, and container runtime behavior. - Keep host and container observations linked to exact node and context. ### 2. Prove Exploit Primitive And Crossover - Show controllable input, trigger condition, affected object, and observable kernel or runtime state change. - Capture before and after identity, namespace, mo