K8s watcher that investigates incidents and opens PRs (it can't merge)
Reference implementation for AI SRE workflows, but it's a blog example not a deployable tool.
Forensic structural audit of kubernetes/kubernetes using The Janitor v7.9.4. Includes CBOM, VEX, and TEI actuarial ledger.
Audit report without the actual tool repo — methodology is interesting, but where's The Janitor?
Kubernetes maintainers, security engineers, DevOps teams
Semgrep · CodeQL · Snyk Code
Reference implementation for AI SRE workflows, but it's a blog example not a deployable tool.
Runs real K8s audits via Trivy and Pluto inside Claude Code skills.
Instead of chasing unreliable "AI fingerprint" heuristics, this action flags PRs using three blunt but practical signals — Velocity (how fast complex changes appear), Shotgun (many unrelated PRs from the same account), and Ghost (account age). It’s a small, sensible tool you can drop into a repo (bundled dist, single triage comment) that will immediately reduce the noise; just watch for false positives around rapid expert contributors and consider tuning thresholds.
Causal DAG tracking catches multi-step exfiltration that per-action security checks completely miss.
Interceptor layer blocks SQL injection and shell injection before agents execute them.
K8s auto-discovery + internal monitoring without inbound ports beats Datadog costs.