runpod-mcp

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to download and install the @runpod/mcp-server package from the official npm registry, which is a well-known service. These tools are provided by the official vendor 'runpod'.
  • [COMMAND_EXECUTION]: The skill utilizes shell commands like npx for installation and curl for verifying connectivity to the hosted API at https://mcp.getrunpod.io/. These operations are consistent with the skill's primary purpose of infrastructure management.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes data from external tool outputs returned by the Runpod REST API.
  • Ingestion points: Untrusted data enters the agent context through tool outputs including list-endpoints, stream-logs, and cost breakdowns.
  • Boundary markers: None explicitly defined in the provided markdown instructions.
  • Capability inventory: The skill possesses capabilities to perform infrastructure CRUD operations (creating and deleting pods/endpoints) and executing shell commands via the allowed Bash tools.
  • Sanitization: There are no documented sanitization or validation steps for the content returned by the external API before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 09:57 PM
Security Audit — agent-trust-hub — runpod-mcp