Atlas / MCP servers / rohitg00 / Kubectl

KubectlBLOCK

mcp/rohitg00/kubectl

Published in CNCF Landscape: A MCP server for Kubernetes.

Verdict
BLOCK
Grade
F
Trust score
49 /100
Exposed tools
12 10r · 1w · 1d
Transport
stdio · streamable-http
License
MIT
Stars
960
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

kubectl-mcp-server

Control your entire Kubernetes infrastructure through natural language conversations with AI. Talk to your clusters like you talk to a DevOps expert. Debug crashed pods, optimize costs, deploy applications, audit security, manage Helm charts, and visualize dashboards, all through natural language. Part of CNCF Landscape, Next to Terraform

Read from source at commit 7486dd044ac8OBSERVED · 2026-09-26
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add kubectl-mcp-server --env KIALI_PASSWORD=${KIALI_PASSWORD} --env KIALI_TOKEN=${KIALI_TOKEN} --env MCP_AUTH_AUDIENCE=${MCP_AUTH_AUDIENCE} --env MCP_AUTH_ENABLED=${MCP_AUTH_ENABLED} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "kubectl-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "KIALI_PASSWORD": "${KIALI_PASSWORD}",
        "KIALI_TOKEN": "${KIALI_TOKEN}",
        "MCP_AUTH_AUDIENCE": "${MCP_AUTH_AUDIENCE}",
        "MCP_AUTH_ENABLED": "${MCP_AUTH_ENABLED}"
      }
    }
  }
}
03

Exposed tools (12)

10 read · 1 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
get_deploymentsreadGet deployments
get_podsreadGet pods
k8s-3d-topologyreadReal-time 3D interactive Kubernetes cluster topology viewer with resource relationships, traffic visualization, and click-to-inspect details
k8s-clusterreadCluster health summary with node status, resource allocation, namespace quotas, and storage overview
k8s-costreadResource utilization analysis with waste detection, right-sizing recommendations, and savings calculator
k8s-deploywriteDeployment management with rollout status, scaling, restart, rollback, and revision history
k8s-eventsreadEvent timeline visualization with type filtering, resource grouping, and time range selection
k8s-helmdestructiveHelm release management with upgrade, rollback, uninstall, values diff, and release notes
k8s-logsreadReal-time log viewer with syntax highlighting, search, filtering by level, and multi-container support
k8s-networkreadNetwork topology graph showing Services, Pods, Ingress connections with click-to-inspect details
k8s-podsreadInteractive pod viewer with filtering, sorting, status indicators, and quick actions (logs, delete, exec)
k8s-proxyreadProxy any kubectl-mcp-server tool call
04

Trust audit

BLOCKgrade F · trust 49/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (7 observation(s))
Network
declared (8 observation(s))
Shell
declared (7 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
evals/claude-code/eval.yaml:58
# Global timeout for the entire eval (seconds)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
evals/openai-agent/eval.yaml:58
# Global timeout for the entire eval (seconds)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
kubectl_mcp_tool/k8s_config.py:149
kubeconfig_env = os.environ.get('KUBECONFIG', '~/.kube/config')
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
kubectl_mcp_tool/k8s_config.py:248
kubeconfig_path = os.environ.get('KUBECONFIG', '~/.kube/config')
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
kubectl_mcp_tool/k8s_config.py:356
kubeconfig_path = os.environ.get('KUBECONFIG', '~/.kube/config')
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
kubectl_mcp_tool/k8s_config.py:501
kubeconfig_path = os.environ.get('KUBECONFIG', '~/.kube/config')
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
kubectl_mcp_tool/k8s_config.py:531
kubeconfig_path = os.environ.get('KUBECONFIG', '~/.kube/config')
Why it matters. touches a credential store
HIGHPrompt injection · prompt.persistence · CWE-94, CWE-1427
kubernetes-skills/claude/k8s-cli/SKILL.md:236
# Add to ~/.bashrc or ~/.zshrc
Why it matters. instructs the agent to persist itself in the user's environment
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/test_server.py:285
text = 'token: "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.test"'
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/test_tools.py:767
text = 'token: "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9"'
MEDIUMSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
kubernetes-skills/claude/k8s-helm/SKILL.md:289
curl https://raw.githubusercontent.com/helm/helm/main/scripts/get-helm-3 | bash
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
k8s-helm
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
charts/kubectl-mcp-server/.helmignore
.helmignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
kubernetes-skills/claude/k8s-helm/references/CHART-STRUCTURE.md:302
echo "Visit http://127.0.0.1:8080 to use your application"
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
README.md:29
<a href="https://aregistry.ai"><img src="https://img.shields.io/badge/agentregistry-verified-blue?logo=data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSIxNiIgaGV
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
kubectl-mcp-app/package.json
@anthropic-ai/sdk, @modelcontextprotocol/sdk, zod, @types/node, @types/react, @types/react-dom, @vitejs/plugin-react, concurrently
Why it matters. 16 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements-dev.txt
pytest, pytest-asyncio, pytest-cov, pytest-mock, black, isort, flake8, mypy
Why it matters. 10 requirement(s) not pinned with ==
Fix. pin exact versions
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
fastmcp, pydantic, fastapi, uvicorn, starlette, kubernetes, PyYAML, requests
Why it matters. 19 requirement(s) not pinned with ==
Fix. pin exact versions
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
kubernetes-skills/claude/k8s-multicluster/CONTEXT-SWITCHING.md:129
# Development: full access SA
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
kubernetes-skills/claude/k8s-vind/references/WORKFLOWS.md:233
| Cluster admin | Full access | Limited |
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:763
curl -fsSL https://raw.githubusercontent.com/agentregistry-dev/agentregistry/main/scripts/install.sh | bash
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:807
curl -fsSL https://raw.githubusercontent.com/kagent-dev/kmcp/refs/heads/main/scripts/get-kmcp.sh | bash
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
deploy/README.md:13
curl -fsSL https://raw.githubusercontent.com/kagent-dev/kmcp/refs/heads/main/scripts/get-kmcp.sh | bash
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
deploy/README.md:52
# Or: curl https://raw.githubusercontent.com/kagent-dev/kagent/refs/heads/main/scripts/get-kagent | bash
INFOInventory / provenance · inv.oversize · CWE-1104
docs/claude/claude-mcp.gif
docs/claude/claude-mcp.gif
Why it matters. 30080077 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-09-26 · audit v0.4.1 · source sha 7486dd044ac8full audit observations/trust-audit/mcp-server/rohitg00__kubectl.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-267486dd044ac8BLOCKF49first audit
06

Questions

What is the Kubectl MCP server?

Published in CNCF Landscape: A MCP server for Kubernetes.

What tools does Kubectl expose?

12 in total: 10 read-only, 1 that write, and 1 that can delete or overwrite (k8s-helm). Every one is listed on this page with its risk.

Is Kubectl safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (49/100) and found 8 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Kubectl need?

It reads KIALI_PASSWORD, KIALI_TOKEN, MCP_AUTH_AUDIENCE, MCP_AUTH_ENABLED, MCP_AUTH_ISSUER, MCP_AUTH_JWKS_URI, MCP_AUTH_REQUIRED_SCOPES, MCP_AUTH_RESOURCE_URL and MCP_BROWSER_PROXY_BYPASS from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Kubectl run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as kubectl-mcp-server at 1.25.0.

How current is this page?

The grade is for one exact copy of the source (7486dd044ac8), read on 2026-09-26. The repository is watched and re-audited when it changes.

Advertisement