{"generated_at":"2026-08-08T12:20:51+00:00","item":{"added_at":"2026-03-31T21:20:01.868000+00:00","analysis_method":"capability_triage","category":"Desktop Extension","description":"MCP Server that can connect to a Kubernetes cluster and manage it.\n\nBy default, the server loads kubeconfig from `~/.kube/config`.\n\nThe server will automatic...","did":"ant-dir-gh-flux159-mcp-server-kubernetes","homepage_url":"https://github.com/Flux159/mcp-server-kubernetes","icon":"https://claude.ai/api/dxt/extensions/ant.dir.gh.flux159.mcp-server-kubernetes/versions/3.4.0/icon.png","id":"ant.dir.gh.flux159.mcp-server-kubernetes","installs":143813,"last_scanned":"","license":"MIT","long_description":"MCP Server that can connect to a Kubernetes cluster and manage it.\n\nBy default, the server loads kubeconfig from `~/.kube/config`.\n\nThe server will automatically connect to your current kubectl context. Make sure you have:\n\n1. kubectl installed and in your PATH\n2. A valid kubeconfig file with contexts configured\n3. Access to a Kubernetes cluster configured for kubectl (e.g. minikube, Rancher Desktop, GKE, etc.)\n4. Optional: Helm v3 installed and in your PATH.\n\nYou can veri...","name":"Kubernetes MCP Server","plutonium_url":"https://plutonium.pluto.security/detail.html?planet=claudesec&did=ant-dir-gh-flux159-mcp-server-kubernetes&utm_source=plutonium_analysis_skill&utm_medium=claude_skill&utm_campaign=connector_risk_assessment","publisher":"Flux159","publisher_url":"https://github.com/Flux159/","repository_url":"https://github.com/Flux159/mcp-server-kubernetes","risk":"high","risk_severity":"high","security_risks":[{"description":"This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.","evidence":"Connector has 22 tools; permissions on claude.ai/directory: \"unknown\". Data flows out of the connected service into the model.","remediation":{"block_tool_categories":[],"steps":["Connect using an account that only has access to the information you actually want Claude to read - not your main admin login.","When you grant access, pick the smallest set of folders, mailboxes, or channels possible.","Check the connector's activity log every so often to make sure nothing unexpected is being read."]},"risk_type":"reads_private_data","severity":"medium","title":"Reads your private information"},{"description":"This connector can execute scripts, shell commands, or arbitrary database queries. In a worst case, an attacker could install software, read files, or pull or change any data its login can reach.","evidence":"12 code execution tools on this connector - e.g. kubectl_get, kubectl_describe, kubectl_apply, kubectl_delete and 8 more.","remediation":{"block_tool_categories":["code_execution"],"steps":["In the tools list below, turn off any tool tagged Block before connecting this to real data or production systems.","If you need code execution, run it on a separate test machine that has no access to your work files, customer data, or saved passwords.","Limit which websites and services that test machine can talk to."]},"risk_type":"runs_code","severity":"high","title":"Can run commands or queries on your behalf"},{"description":"This connector can erase records, files, or accounts. Once deleted the data may be unrecoverable - even an accidental request can cause permanent loss.","evidence":"1 destructive tool on this connector - e.g. uninstall_helm_chart.","remediation":{"block_tool_categories":["destructive"],"steps":["In the tools list below, turn off any tool tagged Block - most workflows don't need Claude to delete anything.","If you really do need deletion, use a login that doesn't have delete permission and have a person handle removals manually.","Make sure the connected service has a trash / recycle bin enabled so accidental deletes can be recovered."]},"risk_type":"deletes_data","severity":"high","title":"Can permanently delete data"}],"signature_status":"unsigned","source_code_reviewed":true,"tags":["reads_private_data","shell_access","database_access","deletes_data","code_deployment"],"tools":[{"description":"","name":"ping"},{"description":"","name":"cleanup"},{"description":"","name":"kubectl_get","risk":{"category":"code_execution","level":"high","recommendation":"Block in production. If needed, scope tightly to a sandboxed account and disallow shell/SQL passthrough.","why":"Runs arbitrary code, queries, or shell commands. Effectively grants the model the same privileges as the configured account on the target system."}},{"description":"","name":"kubectl_describe","risk":{"category":"code_execution","level":"high","recommendation":"Block in production. If needed, scope tightly to a sandboxed account and disallow shell/SQL passthrough.","why":"Runs arbitrary code, queries, or shell commands. Effectively grants the model the same privileges as the configured account on the target system."}},{"description":"","name":"kubectl_apply","risk":{"category":"code_execution","level":"high","recommendation":"Block in production. If needed, scope tightly to a sandboxed account and disallow shell/SQL passthrough.","why":"Runs arbitrary code, queries, or shell commands. Effectively grants the model the same privileges as the configured account on the target system."}},{"description":"","name":"kubectl_delete","risk":{"category":"destructive","level":"high","recommendation":"Block by default. Only enable for read-only or sandbox accounts; require explicit human confirmation for any destructive action.","why":"Irreversibly removes data or resources. A prompt-injection or mistaken instruction could destroy production data with no recovery path."}},{"description":"","name":"kubectl_create","risk":{"category":"code_execution","level":"high","recommendation":"Block in production. If needed, scope tightly to a sandboxed account and disallow shell/SQL passthrough.","why":"Runs arbitrary code, queries, or shell commands. Effectively grants the model the same privileges as the configured account on the target system."}},{"description":"","name":"kubectl_logs","risk":{"category":"code_execution","level":"high","recommendation":"Block in production. If needed, scope tightly to a sandboxed account and disallow shell/SQL passthrough.","why":"Runs arbitrary code, queries, or shell commands. Effectively grants the model the same privileges as the configured account on the target system."}},{"description":"","name":"kubectl_patch","risk":{"category":"code_execution","level":"high","recommendation":"Block in production. If needed, scope tightly to a sandboxed account and disallow shell/SQL passthrough.","why":"Runs arbitrary code, queries, or shell commands. Effectively grants the model the same privileges as the configured account on the target system."}},{"description":"","name":"kubectl_rollout","risk":{"category":"code_execution","level":"high","recommendation":"Block in production. If needed, scope tightly to a sandboxed account and disallow shell/SQL passthrough.","why":"Runs arbitrary code, queries, or shell commands. Effectively grants the model the same privileges as the configured account on the target system."}},{"description":"","name":"kubectl_scale","risk":{"category":"code_execution","level":"high","recommendation":"Block in production. If needed, scope tightly to a sandboxed account and disallow shell/SQL passthrough.","why":"Runs arbitrary code, queries, or shell commands. Effectively grants the model the same privileges as the configured account on the target system."}},{"description":"","name":"kubectl_context","risk":{"category":"code_execution","level":"high","recommendation":"Block in production. If needed, scope tightly to a sandboxed account and disallow shell/SQL passthrough.","why":"Runs arbitrary code, queries, or shell commands. Effectively grants the model the same privileges as the configured account on the target system."}},{"description":"","name":"kubectl_generic","risk":{"category":"code_execution","level":"high","recommendation":"Block in production. If needed, scope tightly to a sandboxed account and disallow shell/SQL passthrough.","why":"Runs arbitrary code, queries, or shell commands. Effectively grants the model the same privileges as the configured account on the target system."}},{"description":"","name":"install_helm_chart","risk":{"category":"code_execution","level":"high","recommendation":"Block in production. If needed, scope tightly to a sandboxed account and disallow shell/SQL passthrough.","why":"Runs arbitrary code, queries, or shell commands. Effectively grants the model the same privileges as the configured account on the target system."}},{"description":"","name":"upgrade_helm_chart","risk":{"category":"code_execution","level":"high","recommendation":"Block in production. If needed, scope tightly to a sandboxed account and disallow shell/SQL passthrough.","why":"Runs arbitrary code, queries, or shell commands. Effectively grants the model the same privileges as the configured account on the target system."}},{"description":"","name":"uninstall_helm_chart","risk":{"category":"destructive","level":"high","recommendation":"Block by default. Only enable for read-only or sandbox accounts; require explicit human confirmation for any destructive action.","why":"Irreversibly removes data or resources. A prompt-injection or mistaken instruction could destroy production data with no recovery path."}},{"description":"","name":"explain_resource"},{"description":"","name":"list_api_resources"},{"description":"","name":"node_management","risk":{"category":"code_execution","level":"high","recommendation":"Block in production. If needed, scope tightly to a sandboxed account and disallow shell/SQL passthrough.","why":"Runs arbitrary code, queries, or shell commands. Effectively grants the model the same privileges as the configured account on the target system."}},{"description":"","name":"exec_in_pod","risk":{"category":"code_execution","level":"high","recommendation":"Block in production. If needed, scope tightly to a sandboxed account and disallow shell/SQL passthrough.","why":"Runs arbitrary code, queries, or shell commands. Effectively grants the model the same privileges as the configured account on the target system."}},{"description":"","name":"port_forward"},{"description":"","name":"stop_port_forward"}],"tools_count":22,"type":"desktop_extension","url":"","uuid":"9b3b4a3c-57e9-5c41-ac62-81f2f2e00ab4","version":"3.4.0"},"query_key":"kubernetes mcp server","schema_version":1,"status":"match"}
