// security
Helm Chart Security Doctor
Audit a Helm chart for insecure defaults before you deploy to Kubernetes.
What it flags
- Privileged containers and allowPrivilegeEscalation.
- Missing resource limits.
- hostPath volumes and host namespace sharing.
- readOnlyRootFilesystem not set.
- runAsNonRoot not enforced.
- Secrets in values.yaml.
- Missing NetworkPolicy and exposed Services.
How to run
Point it at the chart. It parses YAML with the standard library; no Helm, kubectl, or cluster needed. Read-only.
Good to know
Heuristic. It reads chart source as text and does not evaluate templating merged at install time.
Questions
Why Helm specifically?
Default charts often ship insecure, and one bad template propagates across every install.
Does it change anything?
No. It is read-only and uses no network.
Find the insecure default before the cluster does.
Current price and purchase option are shown on Agensi. Instant download. Works with any agent that reads SKILL.md.
Get Helm Chart Security Doctor on Agensi