list_k8s_api_resourcesRetrieves the available API groups and resources from a Kubernetes cluster. This is similar to running `kubectl api-resources`.
check_k8s_authChecks whether an action is allowed on a Kubernetes resource. This is similar to running `kubectl auth can-i`.
describe_k8s_resourceShows the details of a specific Kubernetes resource. This is similar to running `kubectl describe`.
list_k8s_eventsRetrieves events from a Kubernetes cluster. This is similar to running `kubectl events`.
get_k8s_resourceGets one or more Kubernetes resources from a cluster. Resources can be filtered by type, name, namespace, and label selectors. Returns the resources i
get_k8s_cluster_infoGets cluster endpoint information. This is similar to running `kubectl cluster-info`.
get_k8s_versionRetrieves Kubernetes client and server versions for a given cluster. This is similar to running `kubectl version`.
get_k8s_rollout_statusChecks the current rollout status of a Kubernetes resource. This is similar to running `kubectl rollout status`.
list_clustersLists GKE clusters in a given project and location. Location can be a region, zone, or '-' for all locations.
create_clusterCreates a new GKE cluster in a given project and location. It's recommended to read the [GKE documentation](https://docs.cloud.google.com/kubernetes-e
update_clusterUpdates a specific GKE cluster.
get_clusterGets the details of a specific GKE cluster.
list_operationsLists GKE operations in a given project and location. Location can be a region, zone, or '-' for all locations.
get_operationGets the details of a specific GKE operation.
cancel_operationCancels a specific GKE operation.
create_node_poolCreates a node pool for a specific GKE cluster.
list_node_poolsLists the node pools for a specific GKE cluster.
get_node_poolGets the details of a specific node pool within a GKE cluster.
+5 more tools
No proxied traffic observed for this host yet. Connect it at /connect and its grade gains a measured Reliability score + per-tool behavioral evidence — the half a static scan can't produce.
We re-grade container.googleapis.com on a schedule and alert your Slack/webhook the moment its tools change or its grade drops — rug-pull insurance for the connection.
Add the wmcp.sh trust oracle as an MCP server and call grade_mcp_server / check_mcp_drift in your agent's pre-connection gate:
https://wmcp.sh/mcp/trust
readOnly vs observed behavior) layer on via the wmcp.sh proxy.