Ross ROSS = Recommend OSS · open-source software intelligence for agents

cyberark/KubiScan

A tool to scan Kubernetes cluster for risky permissions observed · 2026-08-28

github.com/cyberark/KubiScan · Python · GPL-3.0 (copyleft) observed · 2026-08-28

Health v2 · maintenance only

33/100

  • Activity 23
  • Release rhythm 8
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 2865
  • days_rel: n/a
  • days_push: 465
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1431 stars · 142 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

KubiScan is a Python CLI tool that scans Kubernetes clusters for risky permissions in the RBAC authorization model. It identifies risky roles, bindings, subjects, and pods, and can dump tokens to help administrators reduce cluster attack surface.

Use cases

  • scan kubernetes cluster for risky rbac permissions
  • find over-privileged service accounts in k8s
  • audit rolebindings and clusterrolebindings for excessive access
  • dump service account tokens from pods
  • identify pods with access to secrets
  • check which users can escalate privileges in a cluster

When to choose

  • you need to audit RBAC risk across a large Kubernetes cluster
  • you want automated detection of privilege escalation paths in k8s
  • you run EKS, AKS, or GKE and need RBAC visibility

When to avoid

  • you need continuous runtime security monitoring rather than point-in-time scanning
  • your cluster does not use RBAC authorization
  • you need a GUI-based policy management tool

Facets

cli-tool · maturity active

security authorization vulnerability-scanning security cli python cross-platform kubernetes-rbac cluster-security penetration-testing service-accounts risk-audit containers devops kubernetes docker

1 source

Member repositories

RepositoryRoleHealth v2
cyberark/KubiScanmain33

For agents

markdown · JSON · MCP: product_card(name="cyberark/KubiScan")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem