KubectlBLOCK
Published in CNCF Landscape: A MCP server for Kubernetes.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
kubectl-mcp-server
Control your entire Kubernetes infrastructure through natural language conversations with AI. Talk to your clusters like you talk to a DevOps expert. Debug crashed pods, optimize costs, deploy applications, audit security, manage Helm charts, and visualize dashboards, all through natural language. Part of CNCF Landscape, Next to Terraform
7486dd044ac8OBSERVED · 2026-09-26Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add kubectl-mcp-server --env KIALI_PASSWORD=${KIALI_PASSWORD} --env KIALI_TOKEN=${KIALI_TOKEN} --env MCP_AUTH_AUDIENCE=${MCP_AUTH_AUDIENCE} --env MCP_AUTH_ENABLED=${MCP_AUTH_ENABLED} -- npx -y [email protected]{
"mcpServers": {
"kubectl-mcp-server": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"KIALI_PASSWORD": "${KIALI_PASSWORD}",
"KIALI_TOKEN": "${KIALI_TOKEN}",
"MCP_AUTH_AUDIENCE": "${MCP_AUTH_AUDIENCE}",
"MCP_AUTH_ENABLED": "${MCP_AUTH_ENABLED}"
}
}
}
}Exposed tools (12)
10 read · 1 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
get_deployments | read | Get deployments |
get_pods | read | Get pods |
k8s-3d-topology | read | Real-time 3D interactive Kubernetes cluster topology viewer with resource relationships, traffic visualization, and click-to-inspect details |
k8s-cluster | read | Cluster health summary with node status, resource allocation, namespace quotas, and storage overview |
k8s-cost | read | Resource utilization analysis with waste detection, right-sizing recommendations, and savings calculator |
k8s-deploy | write | Deployment management with rollout status, scaling, restart, rollback, and revision history |
k8s-events | read | Event timeline visualization with type filtering, resource grouping, and time range selection |
k8s-helm | destructive | Helm release management with upgrade, rollback, uninstall, values diff, and release notes |
k8s-logs | read | Real-time log viewer with syntax highlighting, search, filtering by level, and multi-container support |
k8s-network | read | Network topology graph showing Services, Pods, Ingress connections with click-to-inspect details |
k8s-pods | read | Interactive pod viewer with filtering, sorting, status indicators, and quick actions (logs, delete, exec) |
k8s-proxy | read | Proxy any kubectl-mcp-server tool call |
Trust audit
BLOCKgrade F · trust 49/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (7 observation(s))
- Network
- declared (8 observation(s))
- Shell
- declared (7 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
# Global timeout for the entire eval (seconds)
# Global timeout for the entire eval (seconds)
kubeconfig_env = os.environ.get('KUBECONFIG', '~/.kube/config')kubeconfig_path = os.environ.get('KUBECONFIG', '~/.kube/config')kubeconfig_path = os.environ.get('KUBECONFIG', '~/.kube/config')kubeconfig_path = os.environ.get('KUBECONFIG', '~/.kube/config')kubeconfig_path = os.environ.get('KUBECONFIG', '~/.kube/config')# Add to ~/.bashrc or ~/.zshrc
text = 'token: "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.test"'
text = 'token: "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9"'
curl https://raw.githubusercontent.com/helm/helm/main/scripts/get-helm-3 | bash
k8s-helm
.helmignore
echo "Visit http://127.0.0.1:8080 to use your application"
<a href="https://aregistry.ai"><img src="https://img.shields.io/badge/agentregistry-verified-blue?logo=data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSIxNiIgaGV
@anthropic-ai/sdk, @modelcontextprotocol/sdk, zod, @types/node, @types/react, @types/react-dom, @vitejs/plugin-react, concurrently
pytest, pytest-asyncio, pytest-cov, pytest-mock, black, isort, flake8, mypy
fastmcp, pydantic, fastapi, uvicorn, starlette, kubernetes, PyYAML, requests
# Development: full access SA
| Cluster admin | Full access | Limited |
curl -fsSL https://raw.githubusercontent.com/agentregistry-dev/agentregistry/main/scripts/install.sh | bash
curl -fsSL https://raw.githubusercontent.com/kagent-dev/kmcp/refs/heads/main/scripts/get-kmcp.sh | bash
curl -fsSL https://raw.githubusercontent.com/kagent-dev/kmcp/refs/heads/main/scripts/get-kmcp.sh | bash
# Or: curl https://raw.githubusercontent.com/kagent-dev/kagent/refs/heads/main/scripts/get-kagent | bash
docs/claude/claude-mcp.gif
Gates applied: no_behavioural_pass.
7486dd044ac8full audit observations/trust-audit/mcp-server/rohitg00__kubectl.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-26 | 7486dd044ac8 | BLOCK | F | 49 | first audit |
Questions
What is the Kubectl MCP server?
Published in CNCF Landscape: A MCP server for Kubernetes.
What tools does Kubectl expose?
12 in total: 10 read-only, 1 that write, and 1 that can delete or overwrite (k8s-helm). Every one is listed on this page with its risk.
Is Kubectl safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (49/100) and found 8 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Kubectl need?
It reads KIALI_PASSWORD, KIALI_TOKEN, MCP_AUTH_AUDIENCE, MCP_AUTH_ENABLED, MCP_AUTH_ISSUER, MCP_AUTH_JWKS_URI, MCP_AUTH_REQUIRED_SCOPES, MCP_AUTH_RESOURCE_URL and MCP_BROWSER_PROXY_BYPASS from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Kubectl run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as kubectl-mcp-server at 1.25.0.
How current is this page?
The grade is for one exact copy of the source (7486dd044ac8), read on 2026-09-26. The repository is watched and re-audited when it changes.