k8s-security-posture-scorecardAssess Kubernetes cluster security posture across 30 controls covering RBAC, workload security, network policies, IaC, runtime monitoring, and secrets manage...
Install via ClawdBot CLI:
clawdbot install krishnakumarmahadevan-cmd/k8s-security-posture-scorecardGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Sends data to undocumented external endpoint (potential exfiltration)
POST → https://portal.toolweb.in/apis/security/k8scorecardCalls external URL not in known-safe list
https://portal.toolweb.inAudited Apr 17, 2026 · audit v1.0
Generated Apr 6, 2026
A financial services company migrating on-premise applications to AWS EKS needs to validate security compliance before go-live. This skill assesses RBAC, network policies, and secrets management to ensure alignment with PCI-DSS and internal audit requirements, providing a scorecard for stakeholder approval.
A tech startup implementing GitOps with ArgoCD wants to automate security checks in their CI/CD pipeline. The skill evaluates IaC scanning, runtime monitoring, and workload security controls, generating a score after each deployment to track hardening progress and prevent regressions.
A healthcare provider using Azure AKS must demonstrate HIPAA and SOC2 compliance for an upcoming audit. The skill reviews cluster configuration, audit logging, and encryption controls, producing a detailed report with critical findings and remediation steps to address gaps efficiently.
An e-commerce company managing production and staging GKE clusters across regions needs to compare security postures. The skill assesses all 30 controls consistently, highlighting differences in network security and runtime monitoring to prioritize improvements based on risk levels.
A consulting firm trains client teams on Kubernetes best practices and uses this skill to evaluate hands-on labs. It tests understanding of pod security policies, image scanning, and secrets management, providing scores to measure learning outcomes and identify knowledge gaps.
The skill operates via a proprietary API that charges per successful call, tracked through the TOOLWEB_API_KEY. This creates recurring revenue from users conducting regular security assessments, with pricing tiers potentially based on call volume or advanced features like compliance mapping.
Organizations can purchase annual subscriptions for unlimited API access, dedicated support, and custom compliance frameworks. This model targets large teams needing frequent audits, offering predictable billing and integration assistance for scalable security monitoring.
The skill identifies security gaps, enabling the creator to offer follow-on consulting for implementing fixes. Revenue comes from professional services like cluster hardening, training workshops, and managed security reviews, leveraging the scorecard as a lead generation tool.
💬 Integration Tip
Ensure curl and the API key are configured in the environment before use; automate input collection via scripts to streamline repeated assessments across multiple clusters.
Scored Jun 29, 2026
Parse, search, and analyze application logs across formats. Use when debugging from log files, setting up structured logging, analyzing error patterns, correlating events across services, parsing stack traces, or monitoring log output in real time.
Control remote Windows machines via SSH. Use when executing commands on Windows, checking GPU status (nvidia-smi), running scripts, or managing remote Windows systems. Triggers on "run on Windows", "execute on remote", "check GPU", "nvidia-smi", "远程执行", "Windows 命令".
Perform reverse lookup of gTLD domains hosted on a specified nameserver with optional filters by TLD and domain prefix length.
Configure OpenClaw installations with optimized settings, channel setup, security hardening, and production recommendations.
Essential curl commands for HTTP requests, API testing, and file transfers.
Connect to remote desktops via RDP, VNC, and SSH X11 with secure tunneling and troubleshooting.