THRONE
See report Verify server

registry / record

mcp-server-kubernetes

npm / sealed 2026-06-16 / No. 1e718ecc

Does mcp-server-kubernetes MCP work in Claude Code and Cursor? Throne executed mcp-server-kubernetes mcp in a single-use Firecracker microVM and replayed both recorded client behaviours. Compatibility verdict: fit. Is mcp-server-kubernetes mcp safe? Static security scan: 3 finding(s) to review under security ruleset v1. The full per-step results, security findings, scan date, and evidence hash are below.

> throne registry mcp-server-kubernetes sealed
receiptsealed evidence
scan id
1e718ecc18874dd498970c3fec62fb85
target
mcp-server-kubernetes
sealed at
2026-06-16 18:47:31Z
evidence hash
sha256:ef8f99ba090f336451beff8f7dc7845d32643a69e585cc354d49610ef1df65ce
01connectPASS2.4s

initialize ok: server kubernetes 3.9.1, negotiated protocolVersion 2025-11-25, capabilities ['prompts', 'resources', 'tools']

02discoverPASS9ms

supported: tools/list (23 tools), resources/list (5), prompts/list (1)

03validate_schemasPASS64ms

all 23 tool inputSchemas are valid JSON Schema

04smoke_test_toolsPASS68ms

called 10 of 10 tools (cap 10, strategy=serial): 2 ok, 8 returned tool-level errors (expected for synthesized args)

05error_handlingPASS8.4s

structured error responses, connection survived, wrong_type_args: cleanup:accepted (returned result); kubectl_get:error(-32603); kubectl_describe:error(-32603); kubectl_apply:error(-32600); kubectl_delete:error(-32600); unknown_method: error(-32601); invalid_id: no response (silent), connection alive; oversized_input: error(-32600); recovery: accepted (returned result); cancellation: error(-32600); old_version: accepted old version 2024-10-07, negotiated 2024-10-07, server may have stale protocol handling

06streamingNOT_APPLICABLE0ms

no streaming-capable tool declared by this server

07resource_lifecycleWARN4ms

server answered with a structured error instead of completing the step, MCP error -32603: MCP error -32603: Failed to read resource: Error: HTTP protocol is not allowed when skipTLSVerify is not set or false

08concurrent_callsPASS1ms

ladder 1 overlapping cleanup calls: max_observed_stable_concurrency=1; all ids answered exactly once at every level

09reconnectPASS2.3s

transport closed and relaunched; re-handshake ok (protocolVersion 2025-11-25, first session was 2025-11-25)

01connectPASS4.3s

initialize ok: server kubernetes 3.9.1, negotiated protocolVersion 2025-11-25, capabilities ['prompts', 'resources', 'tools'] [request_strategy=pipelined, connection_count=2, second connection established]

02discoverPASS13ms

supported: tools/list (23 tools), resources/list (5), prompts/list (1); notes: connection 2 confirms 23 tools

03validate_schemasPASS59ms

all 23 tool inputSchemas are valid JSON Schema

04smoke_test_toolsPASS57ms

called 10 of 10 tools (cap 10, strategy=pipelined): 2 ok, 8 returned tool-level errors (expected for synthesized args)

05error_handlingPASS8.0s

structured error responses, connection survived, wrong_type_args: cleanup:accepted (returned result); kubectl_get:error(-32603); kubectl_describe:error(-32603); kubectl_apply:error(-32600); kubectl_delete:error(-32600); unknown_method: error(-32601); invalid_id: no response (silent), connection alive; oversized_input: error(-32600); recovery: accepted (returned result); cancellation: error(-32600); old_version: accepted old version 2024-10-07, negotiated 2024-10-07, server may have stale protocol handling

06streamingNOT_APPLICABLE0ms

no streaming-capable tool declared by this server

07resource_lifecycleWARN12ms

server answered with a structured error instead of completing the step, MCP error -32603: MCP error -32603: Failed to read resource: Error: HTTP protocol is not allowed when skipTLSVerify is not set or false

08concurrent_callsPASS9ms

ladder 1/2/4/6 overlapping cleanup calls: max_observed_stable_concurrency=6; all ids answered exactly once at every level

09reconnectPASS4.5s

transport closed and relaunched; re-handshake ok (protocolVersion 2025-11-25, first session was 2025-11-25)

chatgpt desktop calibratingemulation profile pending real-traffic captureCOMING SOON
SECURITY: REVIEW / 3 finding(s) (1 high, 1 medium) / review recommended
HIGH/CRITICAL findings block clean ship. Review before shipping.
HIGHTHR-EXEC-04 / Arbitrary command execution from tool arguments

execFileSync() called with a dynamically built command (heuristic, review): 'file, args, options);'

package/dist/security/kubectl-flags.js:151
LOWTHR-NET-05 / Hardcoded outbound endpoints

1 non-local endpoint host(s) referenced in code, verify each is expected for this server's purpose: attacker (package/dist/security/kubectl-flags.d.ts:19)

package/dist/security/kubectl-flags.d.ts:19
MEDIUMTHR-PROMPT-07 / Prompt injection via tool descriptions

injection-style phrase in source string: 'exfiltrate'

package/dist/security/kubectl-flags.js:7
VERDICT: FIT (HIGH/CRITICAL findings, review before shipping)16 of 18 steps exercised across 2 clientsSANDBOXED RUN, submitted server executed in a disposable microVM, compatibility: 0 fail / 2 warn (16 of 18 steps exercised across 2 clients) / security: review, 3 finding(s), 1 high [SECURITY: 1 high/critical finding(s) block clean ship]sealed by THRONE / No. 1e718ecc / 2026-06-16
scopeattestation tuple
target
mcp-server-kubernetes npm
engine
sandboxed
claude code
calibration: partial recorded=9,spec=0,assumed=9
cursor
calibration: partial recorded=11,spec=0,assumed=7
chatgpt desktop
calibration: unavailable recorded=0,spec=2,assumed=16
steps exercised
16 of 18
test suite
v1.0.0
security ruleset
v1.0.0
sealed at
2026-06-16 18:47:31Z
evidence hash
sha256:ef8f99ba090f336451beff8f7dc7845d32643a69e585cc354d49610ef1df65ce
valid until
2026-09-14
THRONE: FITwear the crown

paste this in your README. it renders the live verdict and links back to this record. if a release ever breaks the verdict, the badge says so on its own.

[![THRONE: FIT](https://api.usethrone.dev/api/badge/mcp-server-kubernetes)](https://usethrone.dev/server/mcp-server-kubernetes)
executed in a disposable microVM, created for this scan and destroyed after it. nothing outlives a run.

maintainer of this server? challenge this record: hello@usethrone.dev. tell us what we got wrong and we re-run it in the open.

this page renders the stored record of a real run. nothing on it is asserted without the execution that proved it.