$npx -y skills add zhaoxuya520/reverse-skill --skill competition-kernel-container-escapeInternal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for kernel attack surface, namespace and cgroup boundaries, container isolation assumptions, syscall paths, and escape primitive verification. Use when the user asks to analyze container-to-host escape p
| 1 | # Competition Kernel Container Escape |
| 2 | |
| 3 | Use this skill only as a downstream specialization after `$ctf-sandbox-orchestrator` is already active and has established sandbox assumptions, node ownership, and evidence priorities. If that has not happened yet, return to `$ctf-sandbox-orchestrator` first. |
| 4 | |
| 5 | Use this skill when the decisive step is proving a boundary crossing between containerized context and host or higher-privilege kernel context. |
| 6 | |
| 7 | Reply in Simplified Chinese unless the user explicitly requests English. |
| 8 | |
| 9 | ## Quick Start |
| 10 | |
| 11 | 1. Map runtime isolation first: namespaces, cgroups, seccomp, capabilities, LSM, and mount boundaries. |
| 12 | 2. Separate exploit prerequisite, primitive, and boundary-crossing proof. |
| 13 | 3. Record kernel version, config hints, runtime options, and reachable syscall surface. |
| 14 | 4. Keep instrumented observations separate from pristine challenge path. |
| 15 | 5. Reproduce one minimal primitive-to-boundary-crossing chain. |
| 16 | |
| 17 | ## Workflow |
| 18 | |
| 19 | ### 1. Map Isolation And Kernel Surface |
| 20 | |
| 21 | - Record namespace map, cgroup mode, capabilities, seccomp profile, AppArmor or SELinux state, mounted filesystems, and runtime sockets. |
| 22 | - Note kernel version, distro build hints, module exposure, and container runtime behavior. |
| 23 | - Keep host and container observations linked to exact node and context. |
| 24 | |
| 25 | ### 2. Prove Exploit Primitive And Crossover |
| 26 | |
| 27 | - Show controllable input, trigger condition, affected object, and observable kernel or runtime state change. |
| 28 | - Capture before and after identity, namespace, mount, or process visibility to prove boundary crossing. |
| 29 | - Distinguish crash-only behavior from stable capability gain. |
| 30 | |
| 31 | ### 3. Reduce To Decisive Escape Chain |
| 32 | |
| 33 | - Compress to: prerequisite state -> primitive trigger -> boundary crossing evidence -> resulting host-level capability. |
| 34 | - State whether root cause is kernel vulnerability, runtime misconfiguration, capability overgrant, or namespace leak. |
| 35 | - If path relies mostly on credential replay after initial foothold, hand off to Linux credential pivot skill. |
| 36 | |
| 37 | ## Read This Reference |
| 38 | |
| 39 | - Load `references/kernel-container-escape.md` for isolation checklist, primitive checklist, and parity guidance. |
| 40 | |
| 41 | ## What To Preserve |
| 42 | |
| 43 | - Kernel and runtime context, capability set, seccomp or LSM state, and namespace map |
| 44 | - Primitive trigger data, boundary crossing evidence, and resulting capability |
| 45 | - One minimal reproducible chain from container context to host-relevant effect |