Atlas / MCP servers / giantswarm / Muster

MusterBLOCK

mcp/giantswarm/muster

Aggregating MCP server: one authenticated endpoint for every MCP server a platform runs, with meta-tool discovery, toolsets, OAuth 2.1 and SSO through Dex, and Kubernetes custom resources

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
13 11r · 2w · 0d
Transport
streamable-http
License
Apache-2.0
Stars
34
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

muster

One MCP endpoint for every MCP server your teams run.

muster is an aggregating Model Context Protocol server. It connects to the MCP servers an organisation runs (a factory's MES and maintenance system, a service desk and its directory, a CRM and an ERP, Kubernetes and Prometheus, in-house tools) and serves all of their tools through a single MCP endpoint. AI agents connect once, discover tools through a small set of meta-tools instead of loading hundreds of tool definitions, and call them under the identity of the person they work for.

It runs as a single binary on a laptop, bridging an IDE to local and remote MCP servers, and as a Kubernetes service that gives a whole organisation one authenticated, observable tool gateway.

What it does

  • Aggregation. Registered MCP servers (stdio, streamable-http, sse) are connected,

health-checked and reco

Read from source at commit 17a4f3444299OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add ats-tests -- uvx ats-tests
claude-desktop
{
  "mcpServers": {
    "ats-tests": {
      "command": "uvx",
      "args": [
        "ats-tests"
      ]
    }
  }
}
03

Exposed tools (13)

11 read · 2 write · 0 destructive.

ToolRiskDescription
areadb
alphareadbeta
core_service_restartwriterestart a running service
core_workflow_listreadlist all workflows
gammareaddelta
prometheus_querywriteRun a query.
prometheus_query_rangereadquery prometheus metrics over a time range
workflow_failing-podsreadInvestigate failing pods in a cluster.
workflow_pod-healthreadReport health of pods across namespaces.
x_kubernetes_listreadList Kubernetes resources such as pods, deployments and services.
x_pd_list_incidentsreadList PagerDuty incidents.
x_pd_list_schedulesreadList PagerDuty on-call schedules.
x_pd_list_servicesreadList PagerDuty services.
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryFAIL
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (4 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
found

Findings (25)

HIGHInventory / provenance · inv.suspicious_name · CWE-1104
internal/testing/scenarios/workflow-execution-payload-truncation.yaml
workflow-execution-payload-truncation.yaml
Why it matters. member named after an attack tool
Fix. remove or justify
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
Makefile.custom.mk:126
docs-serve: ## Serve the documentation site on http://127.0.0.1:8000 with live reload.
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
internal/server/seed_broker_clients_test.go:50
secret   = "broker-client-secret"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
internal/testing/scenarios/oauth-token-injection.yaml:51
token: "test-access-token-12345"
MEDIUMAuth / authz · mcp.remote_no_auth · CWE-287, CWE-862
streamable-http
Why it matters. a network transport with no auth environment variable found
Fix. require a token
LOWInventory / provenance · inv.hidden_file · CWE-1104
.golangci.yml
.golangci.yml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.nancy-ignore
.nancy-ignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.nancy-ignore.generated
.nancy-ignore.generated
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.whitesource
.whitesource
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInformation disclosure · disclose.log_secret · CWE-209, CWE-532
internal/testing/test_tools.go:891
h.logger.Debug("🔐 Injected token for server %s: %s...\n", serverName, token[:min(16, len(token))])
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
internal/client/filesystem/store_test.go:300
"../../" + filepath.Base(outside) + "/escaped",
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
internal/client/filesystem/store_test.go:303
"../../../../../../../.." + outside + "/deep-escape",
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
internal/mcpserver/unsafe_name_test.go:17
"traversal":    "../../evil",
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
internal/reconciler/hardening_test.go:46
resourceType: "../../../etc/passwd",
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
internal/workflow/unsafe_name_test.go:16
"traversal":    "../../evil",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
cmd/agent_test.go:187
endpoint: "http://127.0.0.1:8080/mcp",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
cmd/agent_test.go:202
endpoint: "https://192.168.1.100/mcp",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
internal/aggregator/auth_tools_logout_test.go:337
URL:                "http://127.0.0.1:1/mcp",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
internal/aggregator/connection_helper_test.go:1479
&ServerInfo{Name: "srv", URL: "http://127.0.0.1:0"}, nil)
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/explanation/decisions/006-session-scoped-tool-visibility.md:24
2. **Different tool permissions**: User A authenticated with full permissions, User B with read-only. The MCP server might expose different tools based on the user's authorization.
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/how-to/kubernetes-integration.md:16
- Access to a Kubernetes cluster with valid credentials
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
CHANGELOG.md:30
- **`muster get prompt <name>` and `muster get resource <uri>` find every aggregated prompt and resource, and their completion offers them.** Both looked the item up in the native `prompts/list` and `
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
CHANGELOG.md:70
- **A toolset no longer hides a server's sign-in.** Under an `X-Muster-Toolset` header, a call to a tool of a server the session has not signed in to answers `auth_required` with the sign-in link inst
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
CHANGELOG.md:78
- **A pinned server can receive the person's ID token next to its grant.** A server that acts for the person on two systems needs two of their credentials -- the grant of its pinned authorization serv
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 17a4f3444299full audit observations/trust-audit/mcp-server/giantswarm__muster.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0817a4f3444299BLOCKD69first audit
06

Questions

What is the Muster MCP server?

Aggregating MCP server: one authenticated endpoint for every MCP server a platform runs, with meta-tool discovery, toolsets, OAuth 2.1 and SSO through Dex, and Kubernetes custom resources

What tools does Muster expose?

13 in total: 11 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Muster safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does Muster need?

No credential environment variables were found in its source, so it appears to need none.

How does Muster run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on PyPI as ats-tests.

How current is this page?

The grade is for one exact copy of the source (17a4f3444299), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement