PkgRadar

PyPI · pypi.org

k8s-mcp

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged 0.1.10

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · k8s_mcp-0.1.10/src/k8s_mcp/server/tools/kind.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.10Review122026-06-01
0.1.9Review122026-05-30
0.1.8Review122026-05-30
0.1.7Review122026-05-30
0.1.6Review122026-05-30
0.1.5Review122026-05-30
0.1.4Review122026-05-30
2026.5.27.147Review122026-05-30
0.1.3Review122026-05-30
0.1.2.post145Review122026-05-30
0.1.2.post144Review122026-05-30
0.1.2Review122026-05-30

Block this in CI

PkgRadar gates k8s-mcp (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi k8s-mcp==0.1.10