Atlas / MCP servers / devantler-tech / KSail

KSailBLOCK

mcp/devantler-tech/ksail

All-in-one Kubernetes SDK: create, manage, and operate clusters across distributions (Kind, K3d, Talos, VCluster) with built-in GitOps, secrets, AI assistant, and MCP server. Only requires Docker or a Cloud Provider.

Verdict
BLOCK
Grade
F
Trust score
32 /100
Exposed tools
3 3r · 0w · 0d
Transport
stdio
License
NOASSERTION
Stars
166
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/devantler-tech/ksail/stargazers) [](https://github.com/devantler-tech/ksail/releases/latest) [](https://polyformproject.org/licenses/shield/1.0.0) [](https://pkg.go.dev/github.com/devantler-tech/ksail/v7) [](https://github.com/devantler-tech/ksail/actions/workflows/ci.yaml) [](https://github.com/mcp)

KSail bundles common Kubernetes tooling into a single binary. Spin up local clusters, deploy workloads, and operate cloud-native stacks across distributions and providers through a CLI, VS Code extension, AI chat TUI, or MCP server — with only Docker or access to a Cloud Provider required.

📖 Full documentation:

Quick Install

# Linux / macOS (checksum-verified release)
curl -fsSL https://github.com/devantler-tech/ksail/releases/latest/download/install.sh | sh

# macOS (Homebrew)
brew install --cask devantler-tech/tap/ksail

See the Installation Guide for binary downloads and more options.

AI Assistant Plugins

Install the ksail plugin from the devantler-tech agent plugin marketplace for GitHub Copilot CLI or Claude Code to auto-register ksail's MCP server and a ksai

Read from source at commit fc3a880dd0a5OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code (oci)
claude mcp add ksail:latest -- docker run -i --rm ghcr.io/devantler-tech/ksail:latest:None
03

Exposed tools (3)

3 read · 0 write · 0 destructive.

ToolRiskDescription
contract_requirementsreadValidator interface must have single Validate method accepting typed config
return_typereadValidate method must return *ValidationResult
type_safetyreadValidator interface must be generic with type parameter T
04

Trust audit

BLOCKgrade F · trust 32/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (5 observation(s))
Shell
declared (6 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
pkg/cli/cmd/workload/gen/testdata/tls.key:1
-----BEGIN PRIVATE KEY-----
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
web/ui/src/lib/clusterYaml.ts:38
const parsed = yaml.load(text);
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
pkg/cli/clusterapi/exec.go:58
func (s *Service) Exec(
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
pkg/client/eksctl/client.go:246
func (c *Client) Exec(ctx context.Context, args ...string) ([]byte, []byte, error) {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
pkg/client/eksctl/client.go:270
func (c *Client) exec(
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
pkg/svc/bootstrap/ssh/client.go:212
func (c *Client) exec(
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
pkg/webui/api/exec.go:38
Exec(
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHNetwork egress · net.env_exfil · CWE-200, CWE-319
pkg/svc/chat/docs_generated.go:7
id_rsa ... curl
Why it matters. reads secrets in the same file that sends data out
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
pkg/svc/provisioner/cluster/internal/hetznerbase/verify.go:21
const metadataUserDataEndpoint = "http://169.254.169.254/hetzner/v1/userdata"
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
pkg/svc/provisioner/cluster/internal/hetznerbase/verify.go:25
const metadataServiceHost = "169.254.169.254"
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
HIGHPrompt injection · prompt.fetch_and_trust · CWE-94, CWE-1427
copilot-plugin/skills/ksail/SKILL.md:10
Full docs: <https://ksail.devantler.tech>. Treat the docs site and `ksail <command> --help` as the source of truth; do not paraphrase flag semantics — link users to the relevant page instead.
Why it matters. remote text is to be obeyed as instructions
HIGHPrompt injection · prompt.persistence · CWE-94, CWE-1427
.agents/skills/gh-cli/SKILL.md:2116
# Add to ~/.bashrc or ~/.zshrc
Why it matters. instructs the agent to persist itself in the user's environment
MEDIUMInventory / provenance · inv.binary · CWE-1104
pkg/svc/installer/argocd/Dockerfile.app
Dockerfile.app
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
third_party/go-archive/testdata/broken.tar
broken.tar
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
pkg/cli/cmd/cluster/forget_test.go:204
config.AuthInfos["host"] = &clientcmdapi.AuthInfo{Token: "preserved-host-token"}
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
pkg/svc/bootstrap/kubeadm/config_test.go:94
Token:                "abcdef.0123456789abcdef",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
pkg/svc/bootstrap/kubeadm/config_test.go:132
Token: "abcdef.0123456789abcdef",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
pkg/svc/bootstrap/kubeadm/config_test.go:153
Token:             "abcdef.0123456789abcdef",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
pkg/svc/bootstrap/kubeadm/config_test.go:177
Token:             "abcdef.0123456789abcdef",
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
pkg/svc/state/cluster_state_test.go:257
marker      = "ghp_REGRESSIONSENTINEL000000000000"
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
pkg/svc/bootstrap/cloudinit/cloudinit_test.go:270
private := "-----BEGIN OPENSSH PRIVATE KEY-----\nAAAA\n-----END OPENSSH PRIVATE KEY-----\n"
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
pkg/svc/bootstrap/cloudinit/cloudinit_test.go:304
ED25519Private: "-----BEGIN OPENSSH PRIVATE KEY-----\nAAAA\n-----END OPENSSH PRIVATE KEY-----\n",
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
pkg/svc/bootstrap/cloudinit/cloudinit_test.go:314
private := "-----BEGIN OPENSSH PRIVATE KEY-----\nAAAA\n-----END OPENSSH PRIVATE KEY-----\n"
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
pkg/svc/bootstrap/ssh/write_test.go:91
"-----BEGIN PRIVATE KEY-----\n" + payloadMarker + "\n-----END PRIVATE KEY-----\n",
LOWInventory / provenance · inv.hidden_file · CWE-1104
.coderabbit.yaml
.coderabbit.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose

Gates applied: critical_finding, no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha fc3a880dd0a5full audit observations/trust-audit/mcp-server/devantler-tech__ksail.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07fc3a880dd0a5BLOCKF32first audit
06

Questions

What is the KSail MCP server?

All-in-one Kubernetes SDK: create, manage, and operate clusters across distributions (Kind, K3d, Talos, VCluster) with built-in GitOps, secrets, AI assistant, and MCP server. Only requires Docker or a Cloud Provider.

What tools does KSail expose?

3 in total: 3 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is KSail safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (32/100) and found 12 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does KSail need?

No credential environment variables were found in its source, so it appears to need none.

How does KSail run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as ksail-ui at 0.1.0.

How current is this page?

The grade is for one exact copy of the source (fc3a880dd0a5), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement