Atlas / MCP servers / manusa / Kubernetes

KubernetesBLOCK

mcp/manusa/kubernetes

Model Context Protocol (MCP) server for Kubernetes and OpenShift

Verdict
BLOCK
Grade
F
Trust score
40 /100
Exposed tools
7 7r · 0w · 0d
Transport
stdio · streamable-http
License
Apache-2.0
Stars
2,139
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/containers/kubernetes-mcp-server/blob/main/LICENSE) [](https://www.npmjs.com/package/kubernetes-mcp-server) [](https://pypi.org/project/kubernetes-mcp-server/) [](https://github.com/containers/kubernetes-mcp-server/releases/latest) [](https://github.com/containers/kubernetes-mcp-server/actions/workflows/build.yaml)

✨ Features | 🚀 Getting Started | 🎥 Demos | ⚙️ Configuration | 🛠️ Tools | 💬 Community | 🧑💻 Development

https://github.com/user-attachments/assets/be2b67b3-fc1c-4d11-ae46-93deba8ed98e

✨ Features

A powerful and flexible Kubernetes Model Context Protocol (MCP) server implementation with support for Kubernetes and OpenShift.

  • ✅ Configuration:
  • Automatically detect changes in the Kubernetes configuration and update the MCP server.
  • View and manage the current Kubernetes `.kube/config` or in-cluster configuration.
  • ✅ Generic Kubernetes Resources: Perform operations on any Kubernetes or OpenShift resource.
  • Any CRUD operation (Create or Update, Get, List, Delete).
  • ✅ Pods: Perform Pod-specific operations.
  • List pods in all namespaces or in a specific namespace.
  • Get a pod by name from the specified namespace.
  • Delete a pod by name from the specified
Read from source at commit 0174af942722OBSERVED · 2026-10-01
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code (npm)
claude mcp add kubernetes-mcp-server -- npx -y [email protected]
claude-code (pypi)
claude mcp add kubernetes-mcp-server -- uvx kubernetes-mcp-server==0.0.0
claude-code (oci)
claude mcp add kubernetes-mcp-server:0.0.0 -- docker run -i --rm ghcr.io/containers/kubernetes-mcp-server:0.0.0:None
03

Exposed tools (7)

7 read · 0 write · 0 destructive.

ToolRiskDescription
disabled-toolsetreadDisabled toolset
empty-slice-toolsetreadToolset with empty prompts slice
empty-toolsetreadToolset with no prompts
enabled-toolsetreadEnabled toolset
test-toolsetreadTest toolset with prompts
toolset1readFirst toolset
toolset2readSecond toolset
04

Trust audit

BLOCKgrade F · trust 40/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (8 observation(s))
Network
declared (10 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
found

Findings (25)

CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
pkg/mcplog/log.go:105
regexp.MustCompile(`(-----BEGIN RSA PRIVATE KEY-----)`),
CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
pkg/mcplog/log.go:106
regexp.MustCompile(`(-----BEGIN EC PRIVATE KEY-----)`),
CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
pkg/mcplog/log.go:107
regexp.MustCompile(`(-----BEGIN OPENSSH PRIVATE KEY-----)`),
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
evals/tasks/kubevirt/template-required-params/task.yaml:86
ssh_authorized_keys:
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
pkg/toolsets/kubevirt/vm/troubleshoot/tool.go:595
"ssh_authorized_keys",
Why it matters. touches a credential store
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.claude/skills
.claude/skills
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
evals/core-eval-testing/acp-anthropic/eval-all.yaml
evals/core-eval-testing/acp-anthropic/eval-all.yaml
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
evals/core-eval-testing/acp-anthropic/eval-argo.yaml
evals/core-eval-testing/acp-anthropic/eval-argo.yaml
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
evals/core-eval-testing/acp-anthropic/eval-core.yaml
evals/core-eval-testing/acp-anthropic/eval-core.yaml
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
evals/core-eval-testing/acp-anthropic/eval-helm.yaml
evals/core-eval-testing/acp-anthropic/eval-helm.yaml
Why it matters. link not followed
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
build/browser.mk:15
if curl -fsS http://127.0.0.1:$(BROWSER_MCP_PORT)/healthz >/dev/null; then break; fi; \
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
build/browser.mk:18
curl -fsS http://127.0.0.1:$(BROWSER_MCP_PORT)/healthz >/dev/null || { echo "MCP server did not become ready"; exit 1; }; \
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
build/browser.mk:19
MCP_SERVER_URL="http://127.0.0.1:$(BROWSER_MCP_PORT)/mcp" ./test/browser/run.sh
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
build/conformance.mk:23
'    server: https://127.0.0.1:6443' \
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
build/netobserv.mk:13
@echo "Port-forwarding netobserv-plugin to http://127.0.0.1:$(NETOBSERV_PORT)..."
MEDIUMHard-coded secrets · secret.anthropic · CWE-798, CWE-321
pkg/mcplog/log_test.go:101
msg := "key: sk-ant-api03-ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789-_ABCDEFGHIJKLMNOPQRSTUVWXYZabcde" // notsecret
MEDIUMHard-coded secrets · secret.anthropic · CWE-798, CWE-321
pkg/mcplog/log_test.go:103
s.NotContains(sanitized, "sk-ant-api03-ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789-_ABCDEFGHIJKLMNOPQRSTUVWXYZabcde") // notsecret
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
pkg/mcplog/log_test.go:136
msg := "MONGO_URI=mongodb+srv://dbuser:[email protected]/mydb"
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
pkg/mcplog/log_test.go:73
msg := "token: ghp_1234567890abcdefghijklmnopqrstuv1234" // notsecret
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
pkg/mcplog/log_test.go:75
s.NotContains(sanitized, "ghp_1234567890abcdefghijklmnopqrstuv1234") // notsecret
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
pkg/mcplog/log_test.go:159
msg := `Failed to connect: {"password": "dbpass", "token": "ghp_1234567890abcdefghijklmnopqrstuv1234", "api_key": "sk-proj-ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuv"}`
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
pkg/mcplog/log_test.go:162
s.NotContains(sanitized, "ghp_1234567890abcdefghijklmnopqrstuv1234")
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
pkg/mcplog/log_test.go:115
msg := "key: -----BEGIN RSA PRIVATE KEY-----\nMIIEpAIBAAKCAQEA"
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
pkg/mcplog/log_test.go:117
s.NotContains(sanitized, "-----BEGIN RSA PRIVATE KEY-----")
LOWInventory / provenance · inv.hidden_file · CWE-1104
.mcpbignore
.mcpbignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose

Gates applied: critical_finding, no_behavioural_pass.

Audited 2026-10-01 · audit v0.4.1 · source sha 0174af942722full audit observations/trust-audit/mcp-server/manusa__kubernetes.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-010174af942722BLOCKF40first audit
06

Questions

What is the Kubernetes MCP server?

Model Context Protocol (MCP) server for Kubernetes and OpenShift

What tools does Kubernetes expose?

7 in total: 7 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Kubernetes safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (40/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Kubernetes need?

No credential environment variables were found in its source, so it appears to need none.

How does Kubernetes run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as kubernetes-mcp-server-browser-tests at 0.0.0.

How current is this page?

The grade is for one exact copy of the source (0174af942722), read on 2026-10-01. The repository is watched and re-audited when it changes.

Advertisement