radon-mcp
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted data from the running application (such as logs, component trees, and network traffic), creating a potential surface for indirect prompt injection where malicious data could influence the agent's behavior. \n
- Ingestion points: Data is ingested through tools described in references/view-application-logs.md, references/view-component-tree.md, references/view-network-logs.md, and references/view-network-request-details.md. \n
- Boundary markers: The instructions do not specify the use of delimiters or 'ignore' instructions for the data retrieved from the application. \n
- Capability inventory: The skill includes tools to execute application reloads and rebuilds (references/reload-application.md) and to query external backends for documentation. \n
- Sanitization: The view_network_request_details tool includes a safety mechanism that redacts sensitive headers (e.g., auth, cookie, token, secret, key) before displaying them to the agent. \n- [COMMAND_EXECUTION]: The reload_application tool enables the agent to trigger local system operations, including JS bundle reloads, process restarts, and full native rebuilds, as part of the intended development and debugging workflow. \n- [EXTERNAL_DOWNLOADS]: The skill fetches documentation snippets and library evaluations from the Radon AI backend via the query_documentation and get_library_description tools.
Audit Metadata