Ross ROSS = Recommend OSS · open-source software intelligence for agents

cdk-team/CDK

📦 Make security testing of K8s, Docker, and Containerd easier. observed · 2026-08-28

github.com/cdk-team/CDK · homepage · Go · Apache-2.0 (permissive) observed · 2026-08-28

Health v2 · maintenance only

70/100

  • Activity 80
  • Release rhythm 40
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: 232.0
  • age_days: 2127
  • days_rel: 191
  • days_push: 124
  • n_releases_24m: 3

Full methodology

Adoption not part of the score

4740 stars · 608 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

CDK is a zero-dependency container penetration toolkit written in Go for security testing of Kubernetes, Docker, and Containerd environments. It bundles environment evaluation, PoCs/EXPs for container escape and privilege escalation, and slim net-tools that work inside minimal containers without OS dependencies.

Use cases

  • evaluate a container for exploitable capabilities and misconfigurations
  • escape a privileged or misconfigured container to the host
  • take over a Kubernetes cluster from inside a pod
  • run exploits in slimmed containers lacking curl, wget, or shell tools
  • test container security posture during red team engagements
  • deliver a single static binary into a target container for post-exploitation

When to choose

  • you need a single static binary that runs in minimal/slimmed containers with no OS dependencies
  • you are doing authorized penetration testing or red teaming of K8s or Docker environments
  • you want automated evaluation plus ready-made container escape exploits
  • you need built-in net-tools (nc, kcurl, ifconfig, ps) inside a stripped-down container

When to avoid

  • you need defensive monitoring or compliance scanning rather than offensive exploitation
  • your targets are non-containerized hosts or traditional VMs
  • you lack authorization to test the target systems
  • you need a GUI or Windows-native tooling

Facets

cli-tool · maturity active

penetration-testing security vulnerability-scanning developer-tools security cloud-computing penetration-testing cli container-escape kubernetes-security docker-security exploitation privilege-escalation red-team post-exploitation zero-dependency containers devops linux

2 sources

Member repositories

RepositoryRoleHealth v2
cdk-team/CDKmain70

For agents

markdown · JSON · MCP: product_card(name="cdk-team/CDK")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem