Atlas / MCP servers / yindia / RootCause

RootCauseSAFE

mcp/yindia/rootcause

RootCause is a local-first MCP server that turns natural-language requests into evidence-backed incident analysis, Kubernetes diagnostics, and safer operations.

Verdict
SAFE
Grade
B
Trust score
88 /100
Exposed tools
26 24r · 2w · 0d
Transport
—
License
MIT
Stars
42
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://go.dev/) [](https://modelcontextprotocol.io/) [](https://codecov.io/gh/yindia/rootcause)

AI-native SRE for Kubernetes incidents.

RootCause is a local-first MCP server that turns natural-language requests into evidence-backed incident analysis, Kubernetes diagnostics, and safer operations.

Built in Go as a single binary, RootCause is optimized for low-friction local workflows using your existing kubeconfig identity.

🚀 Quick Start | 🌐 Client Setup | 🛠️ Tools | 🧩 Skills | 🔒 Safety | ⚙️ Config | 🏗️ Architecture | 🤝 Contributing

Why RootCause 💡

RootCause is built for SRE/operator workflows where speed matters, but unsafe automation is unacceptable.

  • 🚀 Stop context-switching: investigate incidents, rollout risk, Helm/Terraform/AWS signals, and remediation from one MCP server.
  • 🧠 AI-powered diagnostics: evidence-first analysis with RCA, timelines, and action-oriented next checks.
  • 💸 Built-in cost optimization: combine resource usage, workload best-practice checks, Terraform plan analysis, and cloud context for optimization decisions.
  • 🔒 Enterprise-ready guardrails: role/namespace policy enforcement, redaction, read-only mode, destructive tool controls, and mutation preflight.
  • ⚡ Zero learning curve: ask natural-language operational questions and use provided prompt templates for common SRE flows.
  • 🌐 Universal compatibility: works with MCP-compatible clients across Claude, Cursor, Copilot, Codex, and more.
  • 🏭 Production-grade workflow: single Go binary, kubeconfig-native auth, deterministic structured outputs, and broad test cove
Read from source at commit 68a4e97d32ecOBSERVED · 2026-10-08
02

Exposed tools (26)

24 read · 2 write · 0 destructive.

ToolRiskDescription
browser_checkreadCheck checkbox or radio element.
browser_clickreadClick an element by selector.
browser_closereadClose browser session.
browser_close_tabreadClose browser tab.
browser_dragreadDrag element from source to target selector.
browser_evaluatereadEvaluate JavaScript expression in current page.
browser_fillreadFill input field with text.
browser_get_htmlreadExtract HTML from element selector.
browser_get_textreadExtract text from element selector.
browser_health_checkwriteRun web health check against application URL.
browser_hoverreadHover over an element by selector.
browser_new_tabreadOpen new tab, optionally with URL.
browser_openreadOpen a URL in browser session.
browser_pdfreadExport current page to PDF.
browser_pressreadPress a keyboard key.
browser_screenshotreadCapture screenshot of current page.
browser_screenshot_grafanareadOpen Grafana URL and capture dashboard screenshot.
browser_selectreadSelect option in dropdown.
browser_snapshotreadCapture page snapshot from current session.
browser_switch_tabreadSwitch active browser tab.
browser_test_ingressreadOpen ingress URL and return basic status evidence.
browser_typereadType text into element by selector.
browser_uncheckreadUncheck checkbox element.
browser_uploadwriteUpload file using file input selector.
browser_wait_forreadWait for selector to appear.
browser_wait_for_urlreadWait for URL to match expected value.
03

Trust audit

SAFEgrade B · trust 88/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (13)

LOWInventory / provenance · inv.hidden_file · CWE-1104
.golangci.yml
.golangci.yml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.goreleaser.yml
.goreleaser.yml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
internal/kube/clients_test.go:90
path := kubeconfigPath("~/.kube/config")
Why it matters. touches a credential store
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
internal/kube/clients_test.go:111
path := kubeconfigPath("~/.kube/config")
Why it matters. touches a credential store
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
internal/mcp/resources_test.go:86
resolved := kubeconfigPath("~/.kube/config")
Why it matters. touches a credential store
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
toolsets/helm/helpers_test.go:18
got := expandHome("~/.kube/config")
Why it matters. touches a credential store
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
toolsets/helm/helpers_test.go:19
if got == "" || got == "~/.kube/config" {
Why it matters. touches a credential store
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
toolsets/helm/ops_more_test.go:193
file.Add(&repo.Entry{Name: "b", URL: "http://127.0.0.1:1/b"})
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
toolsets/helm/ops_more_test.go:194
file.Add(&repo.Entry{Name: "a", URL: "http://127.0.0.1:1/a"})
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
toolsets/helm/ops_more_test.go:232
Arguments: map[string]any{"name": "demo", "url": "http://127.0.0.1:1"},
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
toolsets/k8s/portforward_exec_integration_test.go:24
Host:    "http://127.0.0.1:1",
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
skills/claude/k8s-security/RBAC-PATTERNS.md:93
- Secret access can reveal tokens, keys, and database credentials.
Why it matters. asks the agent to read credentials
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:455
curl -fsSL https://raw.githubusercontent.com/yindia/rootcause/refs/heads/main/install.sh | sh

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 68a4e97d32ecfull audit observations/trust-audit/mcp-server/yindia__rootcause.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0868a4e97d32ecSAFEB88first audit
05

Questions

What is the RootCause MCP server?

RootCause is a local-first MCP server that turns natural-language requests into evidence-backed incident analysis, Kubernetes diagnostics, and safer operations.

What tools does RootCause expose?

26 in total: 24 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is RootCause safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (88/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does RootCause need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (68a4e97d32ec), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement