alexei-led/k8s-mcp-server
MCP server that securely runs kubectl, helm, istioctl, and argocd in a sandbox.
🛡️ AgentReady threat assessment
MAESTRO 7-layer threat model + OWASP AIVSS risk score for alexei-led/k8s-mcp-server, derived from its capabilities.
These scores are auto-generated from public information (the agent's own listing, docs, and repository) using the canonical OWASP AIVSS formula and the MAESTRO framework — an estimate for guidance, not a penetration test, audit, or certification. See the scoring methodology — every score is re-derived by the same automated method as an agent's public evidence changes.
Overview
This server empowers AI assistants to securely execute Kubernetes CLI commands (kubectl, helm, istioctl, argocd) using Unix pipes in a Docker environment. It gives agents cluster control through familiar CLIs. Arbitrary Kubernetes command execution and kubeconfig scope are the core security surfaces.
Key features and capabilities
- kubectl/helm/istioctl/argocd
- Unix pipe support
- Dockerized sandbox
- Multi-arch support
Use cases
- Kubernetes ops via natural language
- Running cluster CLIs through agents