RadarBLOCK
The missing open-source Kubernetes UI with a built-in MCP server for AI agents. See what's broken, why, and what changed. Issues, Topology, event timeline, Helm, GitOps, live service traffic, and cluster audits - all in one Go binary.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
The missing open-source Kubernetes UI. Single binary. No account required. Free forever.
🌐 [radarhq.io](https://radarhq.io) · Docs · Releases
Topology, resources, Helm, GitOps, traffic, audit, upgrade impact, and MCP context for AI agents — from your laptop or in-cluster.
[](https://github.com/skyhook-io/radar/actions/workflows/ci.yml) [](https://github.com/skyhook-io/radar/actions/workflows/codeql.yml) [](https://github.com/skyhook-io/radar/releases/latest) [](https://github.com/skyhook-io/radar/releases) [](https://artifacthub.io/packages/helm/skyhook/radar) [](https://radarhq.io/community/chat) [](LICENSE) [](https://go.dev/)
Table of contents
- Why Radar?
- Installation
- Usage
- Views — T
9bf37b696bedOBSERVED · 2026-09-22Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add radar:1.8.6 -- docker run -i --rm ghcr.io/skyhook-io/radar:1.8.6:None
Trust audit
BLOCKgrade F · trust 44/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (4 observation(s))
- Network
- declared (13 observation(s))
- Shell
- declared (3 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
# Pod exec (opt-in - enables terminal feature)
# Allow pod exec (enables terminal feature)
Exec bool `json:"exec"` // Can create pods/exec (terminal feature)
"set verify=false only when you need a terse write result.",
"verify=false only when you need a terse write result.",
portForwardCmd("svc", h.Resource.Namespace, h.Resource.Name, p.Port)+fmt.Sprintf(" # then: curl -k https://localhost:%d/", p.Port))portForwardCmd("pod", h.Resource.Namespace, name, cp.Port)+fmt.Sprintf(" # then: curl -k https://localhost:%d/", cp.Port))const fmt = (v: number) => v < 1000 ? `${v.toFixed(0)}μs` : `${(v / 1000).toFixed(2)}ms`const fmtUs = (v: number) => v < 1000 ? `${Math.round(v)}μs` : `${(v / 1000).toFixed(2)}ms`{"akia-control", "key=AKIAABCDEFGHIJKLMNOP", "key=[REDACTED]"},RADAR_TEST_POSTGRES_DSN: postgres://radar:radar@localhost:5432/radar?sslmode=disable
DSN: "postgres://radar:[email protected]:1/radar?connect_timeout=1",
DSN: "postgres://radar:[email protected]:1/radar?connect_timeout=1",
DSN: "postgres://radar:[email protected]:1/radar?connect_timeout=1",
Data: map[string]string{"db_credentials": "postgres://app:s3cretpass@db:5432/app"},const token = "rhc_super_secret_literal"
const password = "radar-keyword-secret"
input := "token=ghp_ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghij"
input := "token: ghs_ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghij"
"-----BEGIN RSA PRIVATE KEY-----\nMIIEabc\n-----END RSA PRIVATE KEY-----",
.air.toml
.goreleaser.yaml
.krew.yaml
mkdir -p ~/.kube
token: dummy' > ~/.kube/config
Gates applied: no_behavioural_pass.
9bf37b696bedfull audit observations/trust-audit/mcp-server/skyhook-io__radar.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-22 | 9bf37b696bed | BLOCK | F | 44 | score 45 -> 44 |
| 2026-09-18 | be20d02ffc6b | BLOCK | F | 45 | first audit |
Questions
What is the Radar MCP server?
The missing open-source Kubernetes UI with a built-in MCP server for AI agents. See what's broken, why, and what changed. Issues, Topology, event timeline, Helm, GitOps, live service traffic, and cluster audits - all in one Go binary.
Is Radar safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (44/100) and found 7 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Radar need?
It reads RADAR_CAPTURE_AUTHORIZATION from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Radar run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as @skyhook-io/radar-app at 0.3.1.
How current is this page?
The grade is for one exact copy of the source (9bf37b696bed), read on 2026-09-22. The repository is watched and re-audited when it changes.