<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Headless Cloud Security</title><link>https://docs.sysdig.com/en/release-notes/headless-cloud-security-release-notes/</link><description>Recent content on Headless Cloud Security</description><language>en</language><lastBuildDate>Thu, 07 May 2026 14:36:30 +0100</lastBuildDate><image><url> https://docs.sysdig.com/icons/sysdig-horizontal.png</url><title>Headless Cloud Security</title><link>https://docs.sysdig.com/en/release-notes/headless-cloud-security-release-notes/</link><description>Sysdig logo</description></image><item><title>Headless Cloud Security - 0.1.0 May 06, 2026</title><link>https://docs.sysdig.com/en/release-notes/headless-cloud-security-release-notes/#0.1.0-may-06-2026</link><description>Sysdig Headless Cloud Security packages Sysdig cloud security workflows as reusable agent skills that run inside AI coding agents such as Claude Code. The integration enables users to onboard environments, investigate vulnerabilities and runtime threats, remediate risks, and manage posture workflows without leaving their AI environment.</description><content:encoded>&lt;h4 id="sysdig-headless-cloud-security-public-beta">Sysdig Headless Cloud Security (Public Beta)&lt;/h4>
&lt;p>Sysdig Headless Cloud Security packages Sysdig cloud security workflows as reusable agent skills that run inside AI coding agents such as Claude Code. The integration enables users to onboard environments, investigate vulnerabilities and runtime threats, remediate risks, and manage posture workflows without leaving their AI environment.&lt;/p></content:encoded><guid isPermaLink="false">0.1.0 May 06, 2026</guid></item><item><title>Headless Cloud Security - Install in Claude Code</title><link>https://docs.sysdig.com/en/release-notes/headless-cloud-security-release-notes/#install-in-claude-code</link><description>Added the sysdig-onboarding skill for onboarding cloud accounts and Kubernetes clusters into Sysdig Secure.</description><content:encoded><![CDATA[<ul>

<li><code>/plugin marketplace add sysdig/skills</code></li>

<li><code>/plugin install headless-cloud-security@sysdig-skills</code></li>
</ul>


<h3 id="new-skills">New Skills</h3>
<h4 id="sysdig-onboarding"><code>sysdig-onboarding</code></h4>
<p>Added the <code>sysdig-onboarding</code> skill for onboarding cloud accounts and Kubernetes clusters into Sysdig Secure.</p>

<p>The skill can:</p>

<ul>

<li>Guide you through onboarding interactively or through an autonomous workflow</li>

<li>Generate Terraform configurations for cloud account onboarding</li>

<li>Generate Helm values for Kubernetes onboarding</li>

<li>Validate prerequisites</li>

<li>Deploy onboarding configurations</li>

<li>Verify connectivity after deployment</li>
</ul>


<h4 id="sysdig-investigate"><code>sysdig-investigate</code></h4>
<p>Added the <code>sysdig-investigate</code> skill for identifying and prioritizing vulnerable container images in Sysdig-monitored environments.</p>

<p>The skill can:</p>

<ul>

<li>Rank vulnerable images using configurable risk metrics</li>

<li>Generate remediation plans</li>

<li>Create tracking tickets in Jira, Linear, or GitHub Projects</li>

<li>Recommend assignees using Sysdig risk and exposure signals</li>

<li>Hand off remediation workflows to <code>sysdig-remediate</code></li>
</ul>


<h4 id="sysdig-remediate"><code>sysdig-remediate</code></h4>
<p>Added the <code>sysdig-remediate</code> skill for remediating vulnerable container images.</p>

<p>The skill can:</p>

<ul>

<li>Retrieve Critical and High CVEs from Sysdig</li>

<li>Identify safe fix versions through dependency chain analysis</li>

<li>Generate minimal remediation patches</li>

<li>Open pull requests or merge requests in GitHub or GitLab</li>

<li>Generate <code>.patch</code> files for local repositories</li>

<li>Persist image-to-repository mappings and reviewer history across sessions</li>
</ul>


<h4 id="sysdig-posture"><code>sysdig-posture</code></h4>
<p>Added the <code>sysdig-posture</code> skill for authoring Sysdig Secure Posture custom controls and policies.</p>

<p>The skill supports:</p>

<ul>

<li>Rego-based custom control authoring</li>

<li>Custom policy creation</li>

<li>Terraform generation using the Sysdig Terraform provider</li>

<li>Rego validation</li>

<li>Policy and control discovery workflows</li>
</ul>


<p>API access is read-only. All configuration changes are managed through Terraform.</p>

<h4 id="sysdig-runtime-investigate"><code>sysdig-runtime-investigate</code></h4>
<p>Added the <code>sysdig-runtime-investigate</code> skill for investigating runtime threats detected by Sysdig.</p>

<p>The skill can:</p>

<ul>

<li>Identify the highest-priority runtime threat</li>

<li>Enumerate affected container images</li>

<li>Correlate runtime activity with vulnerabilities</li>

<li>Analyze network blast radius</li>

<li>Perform VirusTotal lookups for suspicious binaries</li>

<li>Escalate investigations to Jira or PagerDuty workflows</li>
</ul>


<h3 id="known-issues">Known Issues</h3>
<ul>

<li>The <code>sysdig-onboarding</code> skill is currently optimized for AWS environments. Expanded Azure and GCP support is planned for upcoming releases.</li>

<li>Claude Code is the primary supported AI coding agent, and the skills are optimized for its capabilities.</li>

<li>Other MCP-compatible agents, including Cursor, OpenAI Codex, and OpenCode, can use the skills through the <code>npx skills</code> CLI command, but are not officially supported at this time.</li>
</ul>]]></content:encoded><guid isPermaLink="false">Install in Claude Code</guid></item></channel></rss>