claude-plugin-kubernetes
PyPI
v0.2.1
Published by an unidentified publisher — no publish provenance and no public repository, so the publisher could not be verified and the source cannot be independently located.
The grade answers one question — how safe is this server for you to adopt — so it is computed in two auditable stages. Nothing below is an opinion or an LLM's guess; every line is a real term the deterministic engine applied, and the same input always yields the same number.
1. Threat score — 100 − 0 = 100. What the published surface and source actually contain:
The deterministic scan raised no scored threat in the surface it inspected — the threat score stayed at 100. Capability observations and advisory notes are recorded but never lower it.
2. Client adoption risk — 100 − 8 = 92. Three small, subtract-only factors that reflect your risk in adopting it — a clean scan proves less on a powerful, unverified or barely-inspectable package, so the grade says so plainly:
| Points | Adoption-risk factor |
|---|---|
| −6 | capability blast radius (high) — client exposure if the model is manipulated |
| −2 | publisher verification (unlinked) — no provenance/repo link, but the shipped source was fully read |
Capability observations and info notes are shown under Findings but never scored.
Open any row's finding below for the file, line and evidence behind a deduction.
Tools that read sensitive data ([k8s_list_secrets]) and tools that can send data out ([k8s_exec]) are exposed together. An agent can move private data to the sink.
Evidence: sources [k8s_list_secrets] → sinks [k8s_exec]
Fix: Keep secret-reading and egress capabilities on separate, separately-approved servers.
Location: flow k8s_list_secrets → k8s_exec
Tool "k8s_exec" appears to run shell commands or evaluate code (keyword "exec" in tool name, parameter "command"). Arbitrary execution driven by model input is one of the most dangerous MCP capabilities; combined with any untrusted input it becomes RCE.
Fix: Sandbox execution, allowlist commands/arguments, and never pass model output to a shell unescaped.
Location: tool k8s_exec
Tool "k8s_exec" takes a command-shaped parameter "command" with no enum/pattern constraint. Free-form, model- or attacker-controlled arguments reaching a shell is the command-injection precondition.
Fix: Constrain the parameter (enum/pattern), or build the command from a fixed template with escaped args.
Location: tool k8s_exec · inputSchema.properties.command
Tool "k8s_exec" can mutate/egress but declares no destructiveHint. Clients that don't default to spec-safe behavior may not prompt before running it.
Fix: Declare accurate annotations, and gate destructive tools on user confirmation regardless.
Location: tool k8s_exec
Each tool and what it can reach — statically extracted from the published source.
k8s_execruns code / shellk8s_list_secretsreads sensitive datak8s_api_resourcesno sensitive capabilityk8s_apply_manifestno sensitive capabilityk8s_cluster_infono sensitive capabilityk8s_delete_podno sensitive capabilityk8s_delete_resourceno sensitive capabilityk8s_describeno sensitive capabilityk8s_diffno sensitive capabilityk8s_find_issuesno sensitive capabilityk8s_getno sensitive capabilityk8s_get_configmap_datano sensitive capabilityk8s_get_contextsno sensitive capabilityk8s_get_yamlno sensitive capabilityk8s_list_configmapsno sensitive capabilityk8s_list_cronjobsno sensitive capabilityk8s_list_daemonsetsno sensitive capabilityk8s_list_deploymentsno sensitive capabilityk8s_list_eventsno sensitive capabilityk8s_list_hpano sensitive capabilityk8s_list_imagesno sensitive capabilityk8s_list_ingressesno sensitive capabilityk8s_list_jobsno sensitive capabilityk8s_list_limitrangesno sensitive capabilityk8s_list_namespacesno sensitive capabilityk8s_list_networkpoliciesno sensitive capabilityk8s_list_nodesno sensitive capabilityk8s_list_poddisruptionbudgetsno sensitive capabilityk8s_list_podsno sensitive capabilityk8s_list_pvcsno sensitive capabilityk8s_list_pvsno sensitive capabilityk8s_list_resourcequotasno sensitive capabilityk8s_list_rolebindingsno sensitive capabilityk8s_list_rolesno sensitive capabilityk8s_list_serviceaccountsno sensitive capabilityk8s_list_servicesno sensitive capabilityk8s_list_statefulsetsno sensitive capabilityk8s_list_storageclassesno sensitive capabilityk8s_logsno sensitive capabilityk8s_logs_selectorno sensitive capabilityk8s_node_operationno sensitive capabilityk8s_patch_resourceno sensitive capabilityk8s_restart_deploymentno sensitive capabilityk8s_rollback_deploymentno sensitive capabilityk8s_rollout_historyno sensitive capabilityk8s_rollout_statusno sensitive capabilityk8s_scaleno sensitive capabilityk8s_self_testno sensitive capabilityk8s_top_nodesno sensitive capabilityk8s_top_podsno sensitive capabilityCross-tool combinations that form a data-exfiltration primitive (untrusted input → sensitive source → external sink).
Scan history per published version. The engine is deterministic — the same version always yields the same score, so a changed score means the package itself changed.
| Version | Score | Findings | Engine | Scanned |
|---|---|---|---|---|
v0.2.1 latest |
A 92/100 | 4 | 1.9.0 | 2026-07-23 |
Show this server's live Trust Score in your README, docs or website. The badge is served straight from the registry and updates automatically after every rescan — no API key needed. It links back to this page, so anyone who sees the grade can also read the findings behind it instead of taking a number on faith.
The score above is reproducible: the same package version always yields the same result. Run it locally or over the free API — no account, no LLM, fully deterministic.
npx mcptrustchecker scan claude-plugin-kubernetes --online --registry pypi
Security scan results for the 1stay MCP server.
Security scan results for the Adguard Home MCP server.
Security scan results for the Ado Browser MCP server.
Security scan results for the Adobe Experience Dev MCP server.
Security scan results for the Aemet MCP server.
Security scan results for the Affinity Mcp Bridge MCP server.