← Back to search
oijusti/k8s-port-forward-mcp

Kubernetes Port Forward MCP

MCP server for discovering Kubernetes services and running kubectl port-forward sessions, optionally with separate log windows.

DECISION SUMMARY
Production trust decision

Not Assessed

Production readiness
Failing
Score
n/a
Percentile pending
Confidence
Not Assessed
Based on evidence completeness, recency, and validation density.
Evidence age
1.4h old
Freshness: never validated. Snapshot trustsnap_89e4beab18d3fad0.
Top risk drivers
  • OAuth or protected-resource evidence is not present
Recommended actions
  • Claim the profile and attach publisher/security evidence
  • Publish OAuth or protected-resource metadata where applicable
  • Keep validation evidence fresh before production approval
Next action
revalidate so the tool surface can be inspected before a production decision is made
tool surface has not been observed by any completed validation run
Compare alternatives Export policy Open report JSON Dispute this assessment
Observed Attention
No observed attention
No observed attention in the current 30-day window.
  • No segmented attention signals observed in the current window.
Bucketed signal based on recent segmented Verify telemetry. Crawler and evaluator activity is not treated as confirmed human demand.
Status
Failing
Score
n/a
Transport
unknown
Tools
0
DISPUTE THIS ASSESSMENT

Dispute this assessment

If any published claim about this server -- its score, a risk flag, a capability classification, or its taxonomy -- is factually wrong, tell us what evidence shows and we will review it. This does not require claiming or verifying ownership of the server first.

Verify responds to disputes within 5 business days and resolves them within 15.

Dispute history

No disputes filed for this server.

Risks

Security posture

No security posture summary available yet.

Tool capability & risk inventory

No tool inventory available from the latest validation run.

Write-action governance

No write-action governance summary is available yet.

Recommended runtime policy
Recommended runtime policy
Not assessed
Default policy stance (medium risk ceiling, write actions require approval, no OAuth requirement). Answers "what may an agent do right now" -- a separate question from production readiness, which answers "how suitable is this server for adoption." Customize via policy export.

No tool surface has been observed yet -- this is not the same as a clean bill of health. Revalidate before treating this server as policy-cleared.

Action-controls diff

Need at least two validation runs before diffing action controls.

Critical alerts
High/critical-severity alerts
0
Production verdicts degrade quickly when high or critical-severity alerts are active.

Compatibility

Client readiness verdicts

No client readiness verdicts are available yet.

Client readiness gate details

No per-client remediation checklist is available yet.

Verdict traces

No verdict trace data is available yet.

Publishability policy profiles

No publishability policy profiles are available yet.

Compatibility fixtures

No compatibility fixtures are available yet.

Recommended for

No recommendation profile is available yet.

Evidence

Current trust snapshot
Snapshot ID
trustsnap_89e4beab18d3fad0
Use this ID to compare server page, report, policy, MCP, homepage, ranking, and shortlist surfaces.
Trust evaluated
Aug 17, 2026 07:08:25 PM UTC
Evidence revision: unknown • materialization: complete
Last validated
Aug 17, 2026 05:42:13 PM UTC
Age: 1.44h • evidence age tier: Never validated • display score: suppressed

Canonical machine links

Evidence confidence
Confidence score
n/a
No evidence-bearing validation runs exist yet for this entry. Confidence cannot be computed.
Live checks captured
0
More direct checks increase trust in the current verdict.
Validation age
n/a
Lower age means fresher evidence.
Latest validation evidence

No validation run available yet.

Known versions
  • No versions recorded.
Public server reputation

No public server reputation signals are available yet.

Benchmark tasks

No benchmark tasks are available yet.

Utility coverage

No utility-coverage summary is available yet.

Tool snapshot diff & changelog

Need at least two validation runs before building a tool changelog.

Validation diff

Need at least two validation runs before diffing changes.

Registry & provenance divergence

No provenance-divergence summary is available yet.

Active alerts

No active alerts for the current server state.

Aliases & registry graph

No aliases discovered for this server.

Alias consolidation

No alias consolidation details are available yet.

Fix it

Why this score?

No score decomposition available yet.

Algorithmic score breakdown
Auth Operability
0/4
Measures whether auth discovery and protected access behave predictably for clients.
Error Contract Quality
0/4
Grades machine-readable error structure, status alignment, and remediation hints.
Rate-Limit Semantics
2/4
Checks whether quota/throttle responses are deterministic and automation-friendly.
Schema Completeness
0/4
Completeness of tool descriptions, parameter docs, examples, and schema shape.
Backward Compatibility
2/4
Stability score across tool schema/name drift relative to prior validations.
SLO Health
0/4
Availability, latency, and burst-failure profile across recent validation history.
Security Hygiene
0/4
HTTPS posture, endpoint hygiene, and response-surface hardening checks.
Task Success
0/4
Can an agent reliably initialize, enumerate tools, and execute core MCP flows?
Trust Confidence
0/4
Confidence-adjusted reliability score that penalizes low evidence volume.
Prompt Contract
0/4
Quality of prompt metadata, argument shape, and prompt discoverability for clients.
Resource Contract
0/4
How completely resources and resource templates describe URIs, types, and usage shape.
Discovery Metadata
1/4
Homepage, docs, icon, repository, support, and license coverage for directory consumers.
Registry Consistency
3/4
Agreement between stored registry metadata, live server-card data, and current validation output.
Installability
0/4
How cleanly a real client can connect, initialize, enumerate tools, and proceed through auth.
Session Semantics
0/4
Determinism and state behavior across repeated MCP calls, including sticky-session surprises.
Tool Surface Design
0/4
Naming clarity, schema ergonomics, and parameter complexity across the tool surface.
Result Shape Stability
0/4
Stability of declared output schemas across validations, with penalties for drift or missing shapes.
OAuth Interop
0/4
Depth and client compatibility of OAuth/OIDC metadata beyond the minimal protected-resource check.
Recovery Semantics
0/4
Whether failures include actionable machine-readable next steps such as retry or upgrade guidance.
Maintenance Signal
1/4
Versioning, update recency, and historical validation cadence that indicate active stewardship.
Adoption Signal
1/4
Directory presence and distribution clues that suggest the server is intended for external use.
Freshness Confidence
0/4
Confidence that recent validations are current enough and dense enough to trust operationally.
Transport Fidelity
0/4
Whether declared transport metadata matches the observed endpoint behavior and response formats.
Spec Recency
0/4
How close the server’s claimed MCP protocol version is to the latest known public revision.
Session Resume
0/4
Whether Streamable HTTP session identifiers and resumed requests behave cleanly for real clients.
Step-Up Auth
0/4
Whether OAuth metadata and WWW-Authenticate challenges support granular, incremental consent instead of broad upfront scopes.
Transport Compliance
0/4
Checks session headers, protocol-version enforcement, session teardown, and expired-session behavior.
Utility Coverage
0/4
Signals support for completions, pagination, and task-oriented utility surfaces that larger clients increasingly expect.
Advanced Capability Coverage
0/4
Coverage of newer MCP surfaces like roots, sampling, elicitation, structured output, and related metadata.
Connector Publishability
0/4
How ready the server looks for client catalogs and managed connector programs.
Tool Snapshot Churn
0/4
Stability of the tool surface across recent validations, including add/remove and output-shape drift.
Connector Replay
0/4
Whether a previously published frozen connector snapshot would remain backward compatible after the latest tool refresh.
Request Association
0/4
Whether roots, sampling, and elicitation appear tied to active client requests instead of arriving unsolicited on idle sessions.
Interactive Flow Safety
0/4
Whether prompts and docs steer users toward safe auth flows instead of pasting secrets directly.
Official Registry Presence
2/4
Whether the server appears directly or indirectly in the official MCP registry.
Safety Transparency
2/4
Clarity of docs, auth disclosure, support links, and other trust signals visible to integrators.
Tool Capability Clarity
0/4
How clearly the tool surface communicates whether each action reads, writes, deletes, executes, or exports data.
Data Exfiltration Resilience
0/4
Assesses export, dump, backup, and bulk-read behavior against the surrounding auth and safeguard signals.
Supply Chain Signal
0/4
Public metadata signal for repository, changelog, license, versioning, and recency that supports supply-chain trust.
Input Sanitization Safety
0/4
Penalizes risky freeform string inputs when schemas do not constrain URLs, code, paths, queries, or templates.
Tool Namespace Clarity
0/4
Measures naming uniqueness and ambiguity across the tool namespace to reduce collision and confusion risk.

8 component(s) not assessed for this run: Abuse/Noise Resilience, Action Safety, Provenance Divergence, Destructive Operation Safety, Egress / SSRF Resilience, Execution / Sandbox Safety, Least Privilege Scope, Secret Handling Hygiene

Experimental candidate components
Personal Data Exposure
0.0
Experimental candidate, weight 0. Export and bulk-access evidence only; no impact on totals, verdicts, rankings, or gates.
Actionable remediation

No remediation items. Current evidence does not show urgent client-facing fixes.

Point loss breakdown

No current score penalties are recorded.

Technical compatibility profiles

No compatibility profiles available.

Governance

MCP TrustOps

TrustOps turns this report into operational controls: validation targets and SLAs, authenticated validation, semantic benchmarks, policy exports, alert subscriptions, badges, cost/compliance metadata, and runtime routing. Fresh trusted index decisions stay separate from long-tail inventory so stale scores do not masquerade as current evidence.

Evidence age tier
Never validated
Policy evidence-age limit (a runtime constraint, distinct from the public 24h freshness window and from a plan's validation target/SLA): 168.0h • confidence-weighted score (display score discounted for evidence age and confidence -- an internal TrustOps input, not the public score): n/a • score suppressed after the 30-day display limit:
Policy exports
Formats: json, rego, yaml, github_action, gateway_config, client_report
Runtime routing
/v1/decide
Returns allowed tools, blocked tools, approval requirement, and reason.
Hosted runtime
Deploy trusted servers from GitHub with secrets, egress controls, releases, rollback, and audit events.
Authenticated validation
Premium publisher feature: paid authenticated runs verify scopes, write-action safeguards, and authorized tool execution.
Active trust badges
none
Semantic benchmarks
template ready
Templates cover GitHub, database, healthcare, web search, and CRM least-privilege jobs.
Supply chain
not scanned
Deep scan checks are marked separately from public metadata signals.
Compliance metadata
Terms, privacy, SOC 2, HIPAA, GDPR, retention, deletion, and audit-log fields are tracked as enterprise metadata.
Alert subscription types
Status changes Score drops or recovers Evidence-age policy breach Validation schema drift OAuth or auth behavior changes Tool surface changes New or changed write tool Supply-chain signal changes Legal or compliance metadata changes
MCP Runtime hosting

No hosted runtime profile is available yet.

Authenticated validation sessions

No authenticated validation detail is available yet.

Public validation is free. Authenticated validation is paid and proves scoped behavior, write-action safeguards, and authenticated tool execution.

Install snippets

No install snippets available.

Agent access & tool surface
Live server tools
No live tool surface captured yet.
Observed from the latest live validation against none. This is the target server surface, not Verify's own inspection tools.
Live capability counts
0 tools • 0 prompts • 0 resources
Counts come from the latest tools/list, prompts/list, and resources/list checks.
Inspect with Verify
search fetch search_servers recommend_servers get_server_report compare_servers
Use Verify itself to search, recommend, compare, and fetch the full report for oijusti/k8s-port-forward-mcp.
Direct machine links

History

Validation history

Trend history appears after at least two validation runs. This avoids presenting a one-point validation as a trend.

Validation timeline

No validation timeline is available yet.

Recent validation runs
Recent validation runs for this MCP server
StartedStatusSummaryLatencyChecks
No validation runs yet.
Incident & change feed

No incidents or changes recorded yet.

Technical details

Raw evidence view
Show raw JSON evidence
{
  "checks": {
    "action_safety_probe": {
      "details": {
        "reason": "empty_observation_set"
      },
      "status": "not_assessed"
    }
  }
}
Capabilities
Use-case taxonomy
No taxonomy tags yet.
Transport compliance drilldown

No transport compliance drilldown is available yet.

Request association

No request-association evidence is available yet.

Connector replay

No connector replay evidence is available yet.