competition-kernel-container-escapelisted
Install: claude install-skill xAmirHamza77/ReverseOps-Skill
# Competition Kernel Container Escape
Use this skill only as a downstream specialization after `$ctf-sandbox-orchestrator` is already active and has established sandbox assumptions, node ownership, and evidence priorities. If that has not happened yet, return to `$ctf-sandbox-orchestrator` first.
Use this skill when the decisive step is proving a boundary crossing between containerized context and host or higher-privilege kernel context.
Reply in Simplified Chinese unless the user explicitly requests English.
## Quick Start
1. Map runtime isolation first: namespaces, cgroups, seccomp, capabilities, LSM, and mount boundaries.
2. Separate exploit prerequisite, primitive, and boundary-crossing proof.
3. Record kernel version, config hints, runtime options, and reachable syscall surface.
4. Keep instrumented observations separate from pristine challenge path.
5. Reproduce one minimal primitive-to-boundary-crossing chain.
## Workflow
### 1. Map Isolation And Kernel Surface
- Record namespace map, cgroup mode, capabilities, seccomp profile, AppArmor or SELinux state, mounted filesystems, and runtime sockets.
- Note kernel version, distro build hints, module exposure, and container runtime behavior.
- Keep host and container observations linked to exact node and context.
### 2. Prove Exploit Primitive And Crossover
- Show controllable input, trigger condition, affected object, and observable kernel or runtime state change.
- Capture before and after identity, namespace, mo