KSailBLOCK
All-in-one Kubernetes SDK: create, manage, and operate clusters across distributions (Kind, K3d, Talos, VCluster) with built-in GitOps, secrets, AI assistant, and MCP server. Only requires Docker or a Cloud Provider.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://github.com/devantler-tech/ksail/stargazers) [](https://github.com/devantler-tech/ksail/releases/latest) [](https://polyformproject.org/licenses/shield/1.0.0) [](https://pkg.go.dev/github.com/devantler-tech/ksail/v7) [](https://github.com/devantler-tech/ksail/actions/workflows/ci.yaml) [](https://github.com/mcp)
KSail bundles common Kubernetes tooling into a single binary. Spin up local clusters, deploy workloads, and operate cloud-native stacks across distributions and providers through a CLI, VS Code extension, AI chat TUI, or MCP server — with only Docker or access to a Cloud Provider required.
📖 Full documentation:
Quick Install
# Linux / macOS (checksum-verified release) curl -fsSL https://github.com/devantler-tech/ksail/releases/latest/download/install.sh | sh # macOS (Homebrew) brew install --cask devantler-tech/tap/ksail
See the Installation Guide for binary downloads and more options.
AI Assistant Plugins
Install the ksail plugin from the devantler-tech agent plugin marketplace for GitHub Copilot CLI or Claude Code to auto-register ksail's MCP server and a ksai
fc3a880dd0a5OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add ksail:latest -- docker run -i --rm ghcr.io/devantler-tech/ksail:latest:None
Exposed tools (3)
3 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
contract_requirements | read | Validator interface must have single Validate method accepting typed config |
return_type | read | Validate method must return *ValidationResult |
type_safety | read | Validator interface must be generic with type parameter T |
Trust audit
BLOCKgrade F · trust 32/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (6 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
-----BEGIN PRIVATE KEY-----
const parsed = yaml.load(text);
func (s *Service) Exec(
func (c *Client) Exec(ctx context.Context, args ...string) ([]byte, []byte, error) {func (c *Client) exec(
func (c *Client) exec(
Exec(
id_rsa ... curl
const metadataUserDataEndpoint = "http://169.254.169.254/hetzner/v1/userdata"
const metadataServiceHost = "169.254.169.254"
Full docs: <https://ksail.devantler.tech>. Treat the docs site and `ksail <command> --help` as the source of truth; do not paraphrase flag semantics — link users to the relevant page instead.
# Add to ~/.bashrc or ~/.zshrc
Dockerfile.app
broken.tar
config.AuthInfos["host"] = &clientcmdapi.AuthInfo{Token: "preserved-host-token"}Token: "abcdef.0123456789abcdef",
Token: "abcdef.0123456789abcdef",
Token: "abcdef.0123456789abcdef",
Token: "abcdef.0123456789abcdef",
marker = "ghp_REGRESSIONSENTINEL000000000000"
private := "-----BEGIN OPENSSH PRIVATE KEY-----\nAAAA\n-----END OPENSSH PRIVATE KEY-----\n"
ED25519Private: "-----BEGIN OPENSSH PRIVATE KEY-----\nAAAA\n-----END OPENSSH PRIVATE KEY-----\n",
private := "-----BEGIN OPENSSH PRIVATE KEY-----\nAAAA\n-----END OPENSSH PRIVATE KEY-----\n"
"-----BEGIN PRIVATE KEY-----\n" + payloadMarker + "\n-----END PRIVATE KEY-----\n",
.coderabbit.yaml
Gates applied: critical_finding, no_behavioural_pass.
fc3a880dd0a5full audit observations/trust-audit/mcp-server/devantler-tech__ksail.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | fc3a880dd0a5 | BLOCK | F | 32 | first audit |
Questions
What is the KSail MCP server?
All-in-one Kubernetes SDK: create, manage, and operate clusters across distributions (Kind, K3d, Talos, VCluster) with built-in GitOps, secrets, AI assistant, and MCP server. Only requires Docker or a Cloud Provider.
What tools does KSail expose?
3 in total: 3 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is KSail safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (32/100) and found 12 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does KSail need?
No credential environment variables were found in its source, so it appears to need none.
How does KSail run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as ksail-ui at 0.1.0.
How current is this page?
The grade is for one exact copy of the source (fc3a880dd0a5), read on 2026-10-07. The repository is watched and re-audited when it changes.