/runtime-security
Claude
runtime-security
Detect and respond to in-container threats at the syscall level using Falco (eBPF-based, CNCF, open-source, no license cost). Covers Falco installation on EKS/GKE with eBPF driver, custom rule authoring, alert routing via Falcosidekick, rule debugging, and bridging Falco runtime signals to Kyverno admission enforcement. Use when asked to "detect privilege escalation in containers", "set up runtime threat detection", "write a Falco rule", "route Falco alerts to Slack", or "debug why my Falco rule is not firing".
More Claude commands
/effort
Set effort
Set the model effort/reasoning level.
/agents
Manage subagents
Create or manage subagents, or edit the agents directory directly.
/team-onboarding
Team onboarding
Generate a team onboarding guide from your usage history.
/deep-research
Deep research
Fan out web searches, cross-check sources, and synthesize a cited report.