SSH and Kubernetes access broker with ephemeral credentials, policy-based access control, and audit logging. Provides MCP tools for executing commands, managing files, and interacting with Kubernetes clusters.
infrabroker demonstrates strong tool design with clear naming conventions, detailed descriptions, and comprehensive parameter schemas. All 13 tools follow verb_noun patterns (ssh_execute, k8s_apply, etc.). Descriptions are generally 150-250 characters and explain what the tool does, when to use it, and prerequisites. All parameters have type definitions and helpful descriptions. However, there are gaps in output schema documentation, return types are not explicitly defined in the visible schema structures, and error handling guidance is minimal. The tool composition is excellent: ssh_* and k8s_* form coherent families with appropriate risk annotations (WRITE, READ_ONLY, DESTRUCTIVE). Parameter relationships are well-documented (e.g., dry_run behavior, sudo constraints, TTL handling). Security practices are sound, no credentials exposed as parameters, risk levels clearly marked. The main weakness is incomplete output schema documentation and missing recovery guidance for error cases.
Apply a Kubernetes manifest (server-side apply / upsert). The manifest is sent as a JSON document. REQUIRES an allow rule for verb=patch; use dry_run=true to preview. May be approval-gated (destructive action).
Delete a Kubernetes object. REQUIRES an allow rule for verb=delete; use dry_run=true to preview. Deletion may be approval-gated (destructive action).
Get one Kubernetes object as JSON. REQUIRES an allow rule for this verb/resource in the cluster policy; if the broker returns not allowed, DO NOT retry — inform the user. Use dry_run=true to preview whether the action is permitted.
List Kubernetes objects of a resource type as JSON, optionally filtered by label/field selectors. Omit namespace to list across all namespaces the ServiceAccount can read. REQUIRES an allow rule; use dry_run=true to preview.
List the Kubernetes clusters accessible to the caller (clusters outside the user's RBAC groups are not listed). ALWAYS call before the other k8s_* tools to learn the available cluster names.
Output schemas not explicitly documented. While input schemas are comprehensive, return types for each tool are inferred but not formally specified in the provided code. LLMs cannot plan downstream tool calls without knowing what fields to expect.
Error handling and recovery guidance minimal. Tools document constraints (e.g., 'If allow_pty=false DO NOT retry') but lack structured error messages that tell LLMs what to do next. Missing actionable error recovery patterns.
No pagination parameters on list tools (ssh_list_servers, k8s_list_clusters). If a user has hundreds of servers or clusters, unbounded results will exhaust context windows. Missing limit, offset/cursor, and total_count fields.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | C | 67 | 2025-06-18+ | v2 |
Read a pod's container logs (plain text). REQUIRES an allow rule for verb=logs; use dry_run=true to preview.
Execute a command on a remote host via SSH with policy-based access control, optional sudo elevation, and dry-run capability to preview policy decisions
Read a file from a remote host via SFTP. Returns the content as base64-encoded data. SHA256 is computed and recorded in the audit log.
List all SSH servers accessible to the caller, including their capabilities (sudo, PTY, file transfer) and jump host configuration. ALWAYS call before other ssh_* tools to learn available host names.
Write a file to a remote host via SFTP. Supports both text and base64-encoded binary content. The file is created or overwritten, with optional permission setting via chmod.
Close an open SSH session and release its resources. No further ssh_session_exec calls are possible on a closed session.
Execute a command within an open SSH session. The command executes in the context established by ssh_session_open (environment, working directory, and shell state are preserved in shell mode).
Open a persistent SSH session on a remote host. The session maintains state across multiple ssh_session_exec calls (shell mode) or runs isolated commands (exec mode). Supports pseudo-terminal mode for interactive programs.
k8s_logs lacks pagination. Requesting tail_lines defaults to 200 but unbounded since_seconds could return massive logs. Missing next_cursor or page token mechanism for large log sets.
Some parameter names could be more explicit. E.g., 'mode' in ssh_session_open accepts 'exec|shell|pty' but could benefit from enum constraint in schema. 'resource' and 'group' in k8s_* tools accept arbitrary strings without format hints for pluralization or API group conventions.