PkgRadar

npm · registry.npmjs.org

mcp-server-kubernetes

Credential file access: matched "KUBECONFIG"

Why PkgRadar flagged 3.6.2

SeveritySignalEvidence
highCredential file accessmatched "KUBECONFIG" · package/dist/tools/exec_in_pod.js
highCredential file accessmatched "KUBECONFIG" · package/dist/tools/helm-operations.js
highCredential file accessmatched "KUBECONFIG" · package/dist/tools/kubectl-apply.js
highCredential file accessmatched "KUBECONFIG" · package/dist/tools/kubectl-context.js
highCredential file accessmatched "KUBECONFIG" · package/dist/tools/kubectl-create.js
highCredential file accessmatched "KUBECONFIG" · package/dist/tools/kubectl-delete.js
highCredential file accessmatched "KUBECONFIG" · package/dist/tools/kubectl-describe.js
highCredential file accessmatched "KUBECONFIG" · package/dist/tools/kubectl-generic.js
highCredential file accessmatched "KUBECONFIG" · package/dist/tools/kubectl-get.js
highCredential file accessmatched "KUBECONFIG" · package/dist/tools/kubectl-logs.js
highCredential file accessmatched "KUBECONFIG" · package/dist/tools/kubectl-operations.js
highCredential file accessmatched "KUBECONFIG" · package/dist/tools/kubectl-patch.js

Scanned versions

VersionVerdictScoreScanned (UTC)
3.6.2Review182026-06-09
3.7.0Review182026-06-09
3.8.0Review182026-06-09
3.9.0Review32026-06-09
3.6.1Review182026-06-09

Block this in CI

PkgRadar gates mcp-server-kubernetes (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]