MusterBLOCK
Aggregating MCP server: one authenticated endpoint for every MCP server a platform runs, with meta-tool discovery, toolsets, OAuth 2.1 and SSO through Dex, and Kubernetes custom resources
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
muster
One MCP endpoint for every MCP server your teams run.
muster is an aggregating Model Context Protocol server. It connects to the MCP servers an organisation runs (a factory's MES and maintenance system, a service desk and its directory, a CRM and an ERP, Kubernetes and Prometheus, in-house tools) and serves all of their tools through a single MCP endpoint. AI agents connect once, discover tools through a small set of meta-tools instead of loading hundreds of tool definitions, and call them under the identity of the person they work for.
It runs as a single binary on a laptop, bridging an IDE to local and remote MCP servers, and as a Kubernetes service that gives a whole organisation one authenticated, observable tool gateway.
What it does
- Aggregation. Registered MCP servers (
stdio,streamable-http,sse) are connected,
health-checked and reco
17a4f3444299OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add ats-tests -- uvx ats-tests
{
"mcpServers": {
"ats-tests": {
"command": "uvx",
"args": [
"ats-tests"
]
}
}
}Exposed tools (13)
11 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
a | read | b |
alpha | read | beta |
core_service_restart | write | restart a running service |
core_workflow_list | read | list all workflows |
gamma | read | delta |
prometheus_query | write | Run a query. |
prometheus_query_range | read | query prometheus metrics over a time range |
workflow_failing-pods | read | Investigate failing pods in a cluster. |
workflow_pod-health | read | Report health of pods across namespaces. |
x_kubernetes_list | read | List Kubernetes resources such as pods, deployments and services. |
x_pd_list_incidents | read | List PagerDuty incidents. |
x_pd_list_schedules | read | List PagerDuty on-call schedules. |
x_pd_list_services | read | List PagerDuty services. |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | FAIL |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (4 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- found
Findings (25)
workflow-execution-payload-truncation.yaml
docs-serve: ## Serve the documentation site on http://127.0.0.1:8000 with live reload.
secret = "broker-client-secret"
token: "test-access-token-12345"
streamable-http
.golangci.yml
.nancy-ignore
.nancy-ignore.generated
.pre-commit-config.yaml
.whitesource
h.logger.Debug("🔐 Injected token for server %s: %s...\n", serverName, token[:min(16, len(token))])"../../" + filepath.Base(outside) + "/escaped",
"../../../../../../../.." + outside + "/deep-escape",
"traversal": "../../evil",
resourceType: "../../../etc/passwd",
"traversal": "../../evil",
endpoint: "http://127.0.0.1:8080/mcp",
endpoint: "https://192.168.1.100/mcp",
URL: "http://127.0.0.1:1/mcp",
&ServerInfo{Name: "srv", URL: "http://127.0.0.1:0"}, nil)2. **Different tool permissions**: User A authenticated with full permissions, User B with read-only. The MCP server might expose different tools based on the user's authorization.
- Access to a Kubernetes cluster with valid credentials
- **`muster get prompt <name>` and `muster get resource <uri>` find every aggregated prompt and resource, and their completion offers them.** Both looked the item up in the native `prompts/list` and `
- **A toolset no longer hides a server's sign-in.** Under an `X-Muster-Toolset` header, a call to a tool of a server the session has not signed in to answers `auth_required` with the sign-in link inst
- **A pinned server can receive the person's ID token next to its grant.** A server that acts for the person on two systems needs two of their credentials -- the grant of its pinned authorization serv
Gates applied: no_behavioural_pass.
17a4f3444299full audit observations/trust-audit/mcp-server/giantswarm__muster.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 17a4f3444299 | BLOCK | D | 69 | first audit |
Questions
What is the Muster MCP server?
Aggregating MCP server: one authenticated endpoint for every MCP server a platform runs, with meta-tool discovery, toolsets, OAuth 2.1 and SSO through Dex, and Kubernetes custom resources
What tools does Muster expose?
13 in total: 11 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Muster safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What credentials does Muster need?
No credential environment variables were found in its source, so it appears to need none.
How does Muster run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on PyPI as ats-tests.
How current is this page?
The grade is for one exact copy of the source (17a4f3444299), read on 2026-10-08. The repository is watched and re-audited when it changes.