MCP server for querying Kubescape vulnerability manifests and security data from Kubernetes clusters
Server defines 3 tools with adequate naming (verb_noun pattern) and reasonable descriptions. However, output schemas are entirely absent, no documentation of what these tools return, which is a critical gap for LLM planning. Parameter descriptions are present but minimal (under 50 chars typically). Error handling is not visible in the source. The tools themselves are straightforward READ_ONLY operations, but lack the depth of documentation expected for production use. Average tool score: 58.
List all vulnerabilities in a given manifest
Discover available vulnerability manifests at image and workload levels
List all vulnerability matches for a given CVE in a given manifest
No output schema documentation for any tool. LLMs cannot determine what fields are returned, complicating downstream chaining and forcing agents to guess at response structure.
Parameter descriptions are terse (under 50 characters). E.g. 'Filter by namespace (optional)' is too brief to guide LLM usage. Should explain what happens when omitted and what the namespace value should be (e.g. Kubernetes namespace name).
No error handling guidance visible in source. Tools do not document what happens on invalid namespace, non-existent manifest, or malformed CVE ID. LLMs need recovery hints ('Call list_vulnerability_manifests first to discover valid names').
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 48 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 44 | - | v1 |
No pagination support visible. list_vulnerability_manifests and list_vulnerabilities_in_manifest return lists but lack limit, offset, or next_cursor parameters. Large result sets could blow context windows.
Tool descriptions do not clarify prerequisites or multi-step workflows. E.g. 'list_vulnerabilities_in_manifest' should hint: 'First call list_vulnerability_manifests to discover valid manifest names.'