KuvaszBLOCK
Kuvasz (pronounce as [ˈkuvɒs]) is an open-source uptime and SSL monitoring service, with multiple notification channels, status pages, IAC support via YAML, Prometheus integration, a complete REST API and many more!
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://github.com/kuvasz-uptime/kuvasz/actions/workflows/main.yml) [](https://github.com/kuvasz-uptime/kuvasz/issues?q=is%3Aissue%20state%3Aopen%20label%3Abug) [](https://codecov.io/gh/kuvasz-uptime/kuvasz) [](https://app.fossa.com/projects/git%2Bgithub.com%2Fkuvasz-uptime%2Fkuvasz?ref=badge_shield) [](https://hub.docker.com/r/kuvaszmonitoring/kuvasz) ---
Kuvasz [ˈkuvɒs] is an open-source, self-hosted uptime & SSL monitoring service with **status pages**, designed to help you keep track of your websites and services. It provides a modern, user-friendly interface, a powerful REST API + MCP server, maintenance windows and supports multiple notification channels like email, Discord, Slack, Telegram, Microsoft Teams, Apprise, Pushover, PagerDuty and custom webhooks.
📖 Documentation
Live demo
You can try out Kuvasz on the dedicated demo instance under https://demo.kuvasz-uptime.dev
Use the following credentials to log in:
- Username:
demo - Password:
secureDemoPassword
🔮 Roadmap
⚡️ Quick start guide
If you want to get started quickly, please refer to the [Deployment guide](https://kuvasz-uptime
da40e58b2c22OBSERVED · 2026-09-29Exposed tools (1)
1 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
MW | read | desc |
Trust audit
BLOCKgrade F · trust 60/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- found
Findings (24)
private const val PKCS8_HEADER = "-----BEGIN PRIVATE KEY-----"
private const val PKCS1_HEADER = "-----BEGIN RSA PRIVATE KEY-----"
private const val SEC1_HEADER = "-----BEGIN EC PRIVATE KEY-----"
gradle-wrapper.jar
apiKeyConfig = ApiKeyConfig().apply { apiKey = "some-non-blank-api-key" },client-secret: 'ThisIsASecretThatIsLongEnoughToBeValidButItIsNotUnique'
client-secret: 'ThisIsASecretThatIsLongEnoughToBeValidButItIsNotUnique'
client-secret: 'ThisIsOnlyA35CharacterLongSecret123'
const val PASSWORD = "e2e-admin-password-123"
.also { Files.writeString(it, "-----BEGIN PRIVATE KEY-----\nMIIE\n") }.also { Files.writeString(it, "-----BEGIN PRIVATE KEY-----\nnot really\n-----END PRIVATE KEY-----\n") }.helmignore
val otherHostMockServerUrl = "http://127.0.0.1:1080"
val address = DockerDaemonUrl.parse("http://10.0.0.5", tls = null)DockerDaemonUrl.parse("http://10.0.0.5", tls = tlsMaterial())val address = DockerDaemonUrl.parse("https://10.0.0.5", tls = null)val address = DockerDaemonUrl.parse("https://10.0.0.5:8443", tls = null)- **Mutual TLS authenticates, but it doesn't authorize.** A valid client certificate gives **full access** to the daemon, so treat the client key as a root credential, and don't reuse it for anything
By default **any user your OIDC provider successfully authenticates is allowed to sign in** and is granted full access. If your provider serves a broader audience than the people who should access _Ku
Without an email allowlist, **every user the OIDC provider can authenticate gets full access to _Kuvasz_** — including the REST API. If your provider is shared with other applications, backed by a pub
Docker hosts are **defined in your configuration file**, similarly to the [integrations](integrations.md), and every monitor refers to its host **by name**. They can't be created or modified on the UI
If it's set to `false`, the authentication will be completely disabled, and you can access the web UI or the API without any credentials.
4. To get your chat ID, send a message to your desired chat and then visit `https://api.telegram.org/bot<YourApiToken>/getUpdates` in your browser, where `<YourApiToken>` is the token you received fro
Once OIDC is enabled, the **Settings** page (and the `/settings` endpoint of the [REST API](../features/api.md)) shows the effective OIDC configuration — the issuer, client ID, the exact redirect (cal
Gates applied: critical_finding, no_behavioural_pass.
da40e58b2c22full audit observations/trust-audit/mcp-server/kuvasz-uptime__kuvasz.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-29 | da40e58b2c22 | BLOCK | F | 60 | first audit |
Questions
What is the Kuvasz MCP server?
Kuvasz (pronounce as [ˈkuvɒs]) is an open-source uptime and SSL monitoring service, with multiple notification channels, status pages, IAC support via YAML, Prometheus integration, a complete REST API and many more!
What tools does Kuvasz expose?
1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Kuvasz safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (60/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Kuvasz need?
No credential environment variables were found in its source, so it appears to need none.
How current is this page?
The grade is for one exact copy of the source (da40e58b2c22), read on 2026-09-29. The repository is watched and re-audited when it changes.