Kubeshark
An MCP server and skills on top of Kubernetes network observability: an agent investigates incidents and queries cluster traffic through an eBPF-built index
Medium risk
We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.
Why this level
- Gives the agent access to cluster network traffic, including decrypted TLS
- Requires installing into production infrastructure via Helm
Install
Manual install
helm repo add kubeshark https://helm.kubeshark.com
helm install kubeshark kubeshark/kubesharkInstalls into a Kubernetes cluster.
This is third-party code. Review the repository files before installing.
What it does
Kubeshark indexes cluster-wide network traffic at the kernel level via eBPF and parses it by protocol, HTTP, gRPC, Redis, Kafka, DNS and more, including TLS decryption with no key management. On top of that it exposes an MCP server so an agent can ask about service errors, trace a specific request across a call chain, or compare retransmit rates between nodes in plain language. It also ships open skills for retrospective root cause analysis from traffic snapshots and for working with the KFL filter language. It installs into a cluster via Helm, and MCP connects through a local CLI command.
Who it is for. For SREs and devops engineers investigating Kubernetes incidents who want that traffic data available to an agent.
Good fit when
- You want to ask an agent why a specific cluster service failed and get an answer grounded in real traffic
- You need to trace a request across several microservices without manually grepping logs
- You need to write and debug traffic filters in the KFL language quickly
Not a fit when
- You only need application logs without the network layer
- You have no access to a Kubernetes cluster or no rights to install Helm charts
Example request
Ask the Kubeshark MCP why checkout failed at 2:15pm and show me the call chainLimitations
Requires installing into a cluster via Helm and relies on eBPF, so it needs matching privileges and kernel support. TLS decryption means access to sensitive traffic, and an ingress controller is recommended over port-forward for production.
How to disable. Remove the MCP server with claude mcp remove kubeshark, and uninstall Kubeshark from the cluster with helm uninstall kubeshark.
MCP
- Transport
- stdio
- Authentication
- not required
Security check
- Gives the agent access to cluster network traffic, including decrypted TLS
- Requires installing into production infrastructure via Helm
README in short
The README positions Kubeshark as network observability for SREs and AI agents: cluster-wide PCAP capture by node, time and workload, traffic visualization with API and Kubernetes semantics, and eBPF-based TLS decryption with no key management. A dedicated AI section covers the MCP server and a table of two open skills, Network RCA and KFL. Install options are Helm, Homebrew or a binary, Apache-2.0 licensed.
FAQ
Does MCP need a separate key?
No, the MCP server runs through the local kubeshark mcp CLI on top of a Kubeshark instance already deployed in the cluster.
How do skills differ from the MCP server?
The MCP server gives the agent tools to query traffic, while the skills (Network RCA and KFL) teach the agent specific workflows built on top of those tools.
Related
An MCP server built into the Netdata agent: metrics, logs, alerts and live process, service and container data for an AI assistant
GitHub's official MCP server: code, issues, pull requests, Actions and security alerts straight from the agent
Agent Skills for Google products
Agent Skills for Google products and technologies
Official Google skill collection for working with Google Cloud, BigQuery, GKE, ads and analytics from an agent
AWS's official MCP server suite: docs, IaC, containers, serverless, databases, cost and monitoring