mirusser/Kubernetes-MCP-Guard
gateway where AI agents observe, plan, and propose remediation that execute only after human approval and digest-bound verification.
What's novel
Outbound plan verification of AI agent output binded to human approval with intent digest and review digest, securing the potential wide blast of agents mutations
Code Analysis
9 files read · 7 roundsA security-first Kubernetes automation system that uses AI agents to detect anomalies, propose bounded fixes via dry-run evidence, and executes only human-approved digest-bound plans through a guarded MCP gateway.
Strengths
Exceptional modularity with clear separation between Observer/Planner/Executor services; implements genuine novel safety pattern combining A2A protocol, OAuth authentication, digest-bound execution, and tool guardrails; production-ready error handling with audit outbox patterns and wall-clock timeouts throughout
Weaknesses
Limited visibility into test coverage from the code read (7/10); some complexity in workflow DAG construction that could benefit from additional documentation for new developers
Score Breakdown
Signal breakdown
Innovation
Craft
Traction
Scope
Evidence
Commits
449
Contributors
2
Files
1140
Active weeks
6
Repository
Language
C#
Stars
0
Forks
0
License
NOASSERTION