RootCauseSAFE
RootCause is a local-first MCP server that turns natural-language requests into evidence-backed incident analysis, Kubernetes diagnostics, and safer operations.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://go.dev/) [](https://modelcontextprotocol.io/) [](https://codecov.io/gh/yindia/rootcause)
AI-native SRE for Kubernetes incidents.
RootCause is a local-first MCP server that turns natural-language requests into evidence-backed incident analysis, Kubernetes diagnostics, and safer operations.
Built in Go as a single binary, RootCause is optimized for low-friction local workflows using your existing kubeconfig identity.
🚀 Quick Start | 🌐 Client Setup | 🛠️ Tools | 🧩 Skills | 🔒 Safety | ⚙️ Config | 🏗️ Architecture | 🤝 Contributing
Why RootCause 💡
RootCause is built for SRE/operator workflows where speed matters, but unsafe automation is unacceptable.
- 🚀 Stop context-switching: investigate incidents, rollout risk, Helm/Terraform/AWS signals, and remediation from one MCP server.
- 🧠 AI-powered diagnostics: evidence-first analysis with RCA, timelines, and action-oriented next checks.
- 💸 Built-in cost optimization: combine resource usage, workload best-practice checks, Terraform plan analysis, and cloud context for optimization decisions.
- 🔒 Enterprise-ready guardrails: role/namespace policy enforcement, redaction, read-only mode, destructive tool controls, and mutation preflight.
- ⚡ Zero learning curve: ask natural-language operational questions and use provided prompt templates for common SRE flows.
- 🌐 Universal compatibility: works with MCP-compatible clients across Claude, Cursor, Copilot, Codex, and more.
- 🏭 Production-grade workflow: single Go binary, kubeconfig-native auth, deterministic structured outputs, and broad test cove
68a4e97d32ecOBSERVED · 2026-10-08Exposed tools (26)
24 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
browser_check | read | Check checkbox or radio element. |
browser_click | read | Click an element by selector. |
browser_close | read | Close browser session. |
browser_close_tab | read | Close browser tab. |
browser_drag | read | Drag element from source to target selector. |
browser_evaluate | read | Evaluate JavaScript expression in current page. |
browser_fill | read | Fill input field with text. |
browser_get_html | read | Extract HTML from element selector. |
browser_get_text | read | Extract text from element selector. |
browser_health_check | write | Run web health check against application URL. |
browser_hover | read | Hover over an element by selector. |
browser_new_tab | read | Open new tab, optionally with URL. |
browser_open | read | Open a URL in browser session. |
browser_pdf | read | Export current page to PDF. |
browser_press | read | Press a keyboard key. |
browser_screenshot | read | Capture screenshot of current page. |
browser_screenshot_grafana | read | Open Grafana URL and capture dashboard screenshot. |
browser_select | read | Select option in dropdown. |
browser_snapshot | read | Capture page snapshot from current session. |
browser_switch_tab | read | Switch active browser tab. |
browser_test_ingress | read | Open ingress URL and return basic status evidence. |
browser_type | read | Type text into element by selector. |
browser_uncheck | read | Uncheck checkbox element. |
browser_upload | write | Upload file using file input selector. |
browser_wait_for | read | Wait for selector to appear. |
browser_wait_for_url | read | Wait for URL to match expected value. |
Trust audit
SAFEgrade B · trust 88/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (13)
.golangci.yml
.goreleaser.yml
path := kubeconfigPath("~/.kube/config")path := kubeconfigPath("~/.kube/config")resolved := kubeconfigPath("~/.kube/config")got := expandHome("~/.kube/config")if got == "" || got == "~/.kube/config" {file.Add(&repo.Entry{Name: "b", URL: "http://127.0.0.1:1/b"})file.Add(&repo.Entry{Name: "a", URL: "http://127.0.0.1:1/a"})Arguments: map[string]any{"name": "demo", "url": "http://127.0.0.1:1"},Host: "http://127.0.0.1:1",
- Secret access can reveal tokens, keys, and database credentials.
curl -fsSL https://raw.githubusercontent.com/yindia/rootcause/refs/heads/main/install.sh | sh
Gates applied: no_behavioural_pass.
68a4e97d32ecfull audit observations/trust-audit/mcp-server/yindia__rootcause.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 68a4e97d32ec | SAFE | B | 88 | first audit |
Questions
What is the RootCause MCP server?
RootCause is a local-first MCP server that turns natural-language requests into evidence-backed incident analysis, Kubernetes diagnostics, and safer operations.
What tools does RootCause expose?
26 in total: 24 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is RootCause safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (88/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does RootCause need?
No credential environment variables were found in its source, so it appears to need none.
How current is this page?
The grade is for one exact copy of the source (68a4e97d32ec), read on 2026-10-08. The repository is watched and re-audited when it changes.