radon-mcp

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted data from the running application (such as logs, component trees, and network traffic), creating a potential surface for indirect prompt injection where malicious data could influence the agent's behavior. \n
  • Ingestion points: Data is ingested through tools described in references/view-application-logs.md, references/view-component-tree.md, references/view-network-logs.md, and references/view-network-request-details.md. \n
  • Boundary markers: The instructions do not specify the use of delimiters or 'ignore' instructions for the data retrieved from the application. \n
  • Capability inventory: The skill includes tools to execute application reloads and rebuilds (references/reload-application.md) and to query external backends for documentation. \n
  • Sanitization: The view_network_request_details tool includes a safety mechanism that redacts sensitive headers (e.g., auth, cookie, token, secret, key) before displaying them to the agent. \n- [COMMAND_EXECUTION]: The reload_application tool enables the agent to trigger local system operations, including JS bundle reloads, process restarts, and full native rebuilds, as part of the intended development and debugging workflow. \n- [EXTERNAL_DOWNLOADS]: The skill fetches documentation snippets and library evaluations from the Radon AI backend via the query_documentation and get_library_description tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:12 AM
Security Audit — agent-trust-hub — radon-mcp