Atlas / MCP servers / flux159 / Kubernetes Manager

Kubernetes ManagerBLOCK

mcp/flux159/kubernetes-manager

MCP Server for kubernetes management commands

Verdict
BLOCK
Grade
D
Trust score
68 /100
Exposed tools
28 17r · 9w · 2d
Transport
sse · stdio · streamable-http
License
MIT
Stars
1,594
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/yourusername/mcp-server-kubernetes/actions/workflows/ci.yml) [](https://github.com/yourusername/mcp-server-kubernetes) [](https://kubernetes.io/) [](https://www.docker.com/) [](https://github.com/Flux159/mcp-server-kubernetes/stargazers) [](https://github.com/Flux159/mcp-server-kubernetes/issues) [](https://github.com/Flux159/mcp-server-kubernetes/pulls) [](https://github.com/Flux159/mcp-server-kubernetes/commits/main)

MCP Server that can connect to a Kubernetes cluster and manage it. Supports loading kubeconfig from multiple sources in priority order.

https://github.com/user-attachments/assets/f25f8f4e-4d04-479b-9ae0-5dac452dd2ed

Installation & Usage

Prerequisites

Before using this MCP server with any tool, make sure you have:

  1. kubectl installed and in your PATH
  2. A valid kubeconfig file with contexts configured
  3. Access to a Kubernetes cluster configured for kubectl (e.g. minikube, Rancher Desktop, GKE, etc.)
  4. Helm v3 installed and in your PATH (no Tiller required). Optional if you don't plan to use Helm.

You can verify your connection by running kubectl get pods in a termina

Read from source at commit 85489fe48a8dOBSERVED · 2026-09-24
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-server-kubernetes --env K8S_TOKEN=${K8S_TOKEN} --env MASK_SECRETS=${MASK_SECRETS} --env MCP_AUTH_TOKEN=${MCP_AUTH_TOKEN} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-server-kubernetes": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "K8S_TOKEN": "${K8S_TOKEN}",
        "MASK_SECRETS": "${MASK_SECRETS}",
        "MCP_AUTH_TOKEN": "${MCP_AUTH_TOKEN}"
      }
    }
  }
}
03

Exposed tools (28)

17 read · 9 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
cleanupreadCleanup all managed resources
create_deploymentwriteCreate a new Kubernetes deployment
exec_in_podwriteExecute a command in a Kubernetes pod or container and return the output. Command must be an array of strings where the first element is the executable and remaining elements are arguments. This executes directly without shell interpretation for security.
explain_resourcereadGet documentation for a Kubernetes resource or field
install_helm_chartwriteInstall a Helm chart with support for both standard and template-based installation
k8s-diagnosereadDiagnose Kubernetes Resources.
keywordreadA keyword to search pod/node names.
kubectl_applywriteApply a Kubernetes YAML manifest from a string or file
kubectl_contextwriteManage Kubernetes contexts - list, get, or set the current context
kubectl_createwriteCreate Kubernetes resources using various methods (from file or using subcommands)
kubectl_deletedestructiveDelete Kubernetes resources by resource type, name, labels, or from a manifest file
kubectl_describereadDescribe Kubernetes resources by resource type, name, and optionally namespace
kubectl_genericwriteExecute any kubectl command with the provided arguments and flags
kubectl_getreadGet or list Kubernetes resources by resource type, name, and optionally namespace
kubectl_logsreadGet logs from Kubernetes resources like pods, deployments, or jobs
kubectl_patchwriteUpdate field(s) of a resource using strategic merge patch, JSON merge patch, or JSON patch
kubectl_reconnectreadReconnect to the Kubernetes API server by recreating all API clients. Use this after cluster upgrades (e.g., EKS control plane upgrades that rotate ENIs/IPs) to force fresh DNS resolution and new TCP connections.
kubectl_rolloutreadManage the rollout of a resource (e.g., deployment, daemonset, statefulset)
kubectl_scalereadScale a Kubernetes deployment
list_api_resourcesreadList the API resources available in the cluster
list_namespacesreadList all namespaces
namespacereadOptional: Specify a namespace to narrow down the search.
node_managementreadManage Kubernetes nodes with cordon, drain, and uncordon operations
pingreadVerify that the counterpart is still responsive and the connection is alive.
port_forwardreadForward a local port to a port on a Kubernetes resource
stop_port_forwardwriteStop a port-forward process
uninstall_helm_chartdestructiveUninstall a Helm chart release
upgrade_helm_chartreadUpgrade an existing Helm chart release
04

Trust audit

BLOCKgrade D · trust 68/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (5 observation(s))
Shell
declared (1 observation(s))
Dependencies
pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
src/tools/kubectl-get.ts:578
const parsed = yaml.load(output);
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
helm-chart/values.yaml:619
#   - "199.36.153.8/30" # metadata.google.internal
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
helm-chart/values.yaml:625
# Cloud provider metadata service (AWS/GCP use same IP: 169.254.169.254)
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
MEDIUMInventory / provenance · inv.binary · CWE-1104
bun.lockb
bun.lockb
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
src/security/kubectl-flags.ts:232
`act on the MCP server's own host, which would allow exfiltration of ` +
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
helm-chart/examples/custom-kubeconfig.yaml:327
vault-token: "your-vault-token-here"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
helm-chart/examples/custom-kubeconfig.yaml:333
token: "your-service-account-token"
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
kubectl_delete, uninstall_helm_chart
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.mcpbignore
.mcpbignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.symlink · CWE-1104
AGENTS.md
AGENTS.md
Why it matters. link not followed
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
.github/workflows/cd.yml:56
sed -i 's|https://192.168.49.2:8443|http://localhost:8080|g' ~/.kube/config
Why it matters. touches a credential store
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
.github/workflows/cd.yml:59
grep "server:" ~/.kube/config
Why it matters. touches a credential store
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
.github/workflows/cd.yml:73
sed -i 's|http://localhost:8080|https://192.168.49.2:8443|g' ~/.kube/config
Why it matters. touches a credential store
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
.github/workflows/ci.yml:45
sed -i 's|https://192.168.49.2:8443|http://localhost:8080|g' ~/.kube/config
Why it matters. touches a credential store
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
.github/workflows/ci.yml:48
grep "server:" ~/.kube/config
Why it matters. touches a credential store
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
helm-chart/examples/secure-networkpolicy.yaml:142
cidr: 169.254.169.254/32  # AWS metadata service
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
helm-chart/examples/secure-networkpolicy.yaml:161
cidr: 169.254.169.254/32  # GCP metadata service
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
helm-chart/examples/secure-networkpolicy.yaml:193
#    - Metadata services (169.254.169.254)
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/kubectl-flags-security.unit.test.ts:250
server: "https://127.0.0.1:19001",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/kubectl-flags-security.unit.test.ts:354
assertSafeArgv(["get", "pods", "-Ashttp://127.0.0.1:59999"])
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/kubectl-flags-security.unit.test.ts:572
name: "--server=https://127.0.0.1:19012",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/kubectl-flags-security.unit.test.ts:595
resourceType: "--server=https://127.0.0.1:19099",
LOWNetwork egress · net.tls_off · CWE-200, CWE-319
helm-chart/examples/secure-networkpolicy.yaml:200
#    kubectl exec -it deployment/mcp-server -- curl -k https://kubernetes.default/api
Why it matters. certificate verification is disabled
Fix. leave verification on
LOWNetwork egress · net.tls_off · CWE-200, CWE-319
tests/kubectl-flags-security.unit.test.ts:32
test("rejects --insecure-skip-tls-verify", () => {
Why it matters. certificate verification is disabled
Fix. leave verification on
LOWNetwork egress · net.tls_off · CWE-200, CWE-319
tests/kubectl-flags-security.unit.test.ts:124
test("rejects --insecure-skip-tls-verify=true in args", () => {
Why it matters. certificate verification is disabled
Fix. leave verification on

Gates applied: no_behavioural_pass.

Audited 2026-09-24 · audit v0.4.1 · source sha 85489fe48a8dfull audit observations/trust-audit/mcp-server/flux159__kubernetes-manager.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-2485489fe48a8dBLOCKD68first audit
06

Questions

What is the Kubernetes Manager MCP server?

MCP Server for kubernetes management commands

What tools does Kubernetes Manager expose?

28 in total: 17 read-only, 9 that write, and 2 that can delete or overwrite (kubectl_delete, uninstall_helm_chart). Every one is listed on this page with its risk.

Is Kubernetes Manager safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (68/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Kubernetes Manager need?

It reads K8S_TOKEN, MASK_SECRETS and MCP_AUTH_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Kubernetes Manager run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as mcp-server-kubernetes at 4.1.7.

How current is this page?

The grade is for one exact copy of the source (85489fe48a8d), read on 2026-09-24. The repository is watched and re-audited when it changes.

Advertisement