{"generated_at":"2026-09-18T12:54:00+00:00","item":{"added_at":"2026-07-23","analysis_method":"capability_triage","category":"Web Connector","description":"Create, deploy, and manage your Render cloud infrastructure with natural language.","did":"045e9791-ed0d-4dfb-8271-a2f1ff62f9f0","homepage_url":"https://render.com/","icon":"https://assets.render.com/brands/logos/render-logomark-black.svg","id":"045e9791-ed0d-4dfb-8271-a2f1ff62f9f0","installs":0,"last_scanned":"","license":"","long_description":"Render's official MCP server lets AI apps and agents manage your Render infrastructure through natural language. Create and deploy web services, static sites, and cron jobs; provision Render Postgres and Key Value instances; trigger and inspect deploys; update environment variables and compute plans; stream logs; analyze performance metrics; and run read-only SQL against your Postgres — all scoped to a workspace you choose. Hosted by Render at https://mcp.render.com/mcp, it connects over OAuth (or a Render API key) and is designed to keep secrets like connection strings out of your AI app's context.","name":"Render","plutonium_url":"https://plutonium.pluto.security/detail.html?planet=claudesec&did=045e9791-ed0d-4dfb-8271-a2f1ff62f9f0&utm_source=plutonium_analysis_skill&utm_medium=claude_skill&utm_campaign=connector_risk_assessment","publisher":"Render","publisher_url":"https://render.com/","repository_url":"","risk":"high","risk_severity":"high","security_risks":[{"description":"This connector can execute scripts, shell commands, or arbitrary database queries. In a worst case, an attacker could install software, read files, or pull or change any data its login can reach.","evidence":"1 observed tool(s): trigger_deploy.","remediation":{"block_tool_categories":["code_execution"],"steps":["In the tools list below, turn off any tool tagged Block before connecting this to real data or production systems.","If you need code execution, run it on a separate test machine that has no access to your work files, customer data, or saved passwords.","Limit which websites and services that test machine can talk to."]},"risk_type":"runs_code","severity":"high","title":"Can run commands or queries on your behalf"},{"description":"This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.","evidence":"9 observed tool(s): create_cron_job, create_key_value, create_postgres, create_static_site, create_web_service, update_cron_job, ….","remediation":{"block_tool_categories":["state_change"],"steps":["Try the connector on a test account first to see what it changes before letting it touch your real records.","Where the connected service supports it, give Claude read-only access and only allow writes for the specific things you need updated.","In the tools list below, turn off any tool you don't actively need - the ones tagged Block are the most important to disable."]},"risk_type":"modifies_data","severity":"medium","title":"Can change or update your information"},{"description":"This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.","evidence":"14 observed tool(s): get_deploy, get_key_value, get_metrics, get_postgres, get_selected_workspace, get_service, ….","remediation":{"block_tool_categories":[],"steps":["Connect using an account that only has access to the information you actually want Claude to read - not your main admin login.","When you grant access, pick the smallest set of folders, mailboxes, or channels possible.","Check the connector's activity log every so often to make sure nothing unexpected is being read."]},"risk_type":"reads_private_data","severity":"low","title":"Reads your private information"},{"description":"Anything you share with this connector flows through one or more third-party services. Those companies see, store, and may use the data according to their own policies.","evidence":"1 observed tool(s): [remote publisher endpoint].","remediation":{"block_tool_categories":[],"steps":["Treat anything you tell this connector as if you sent it directly to the third-party company - because you did.","Check how long that company keeps your data and how to delete it.","Avoid putting health info, customer names, or payment details into this connector unless you have a written agreement with that company."]},"risk_type":"forwards_data_to_third_party","severity":"low","title":"Sends your data to outside companies"}],"signature_status":"unknown","source_code_reviewed":false,"tags":["code_deployment","database_access","forwards_data_to_third_party","modifies_data","network_access","reads_private_data","runs_code","web_connector"],"tools":[{"description":"","name":"create_cron_job","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"","name":"create_key_value","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"","name":"create_postgres","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"","name":"create_static_site","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"","name":"create_web_service","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"","name":"get_deploy"},{"description":"","name":"get_key_value"},{"description":"","name":"get_metrics"},{"description":"","name":"get_postgres"},{"description":"","name":"get_selected_workspace"},{"description":"","name":"get_service"},{"description":"","name":"list_deploys"},{"description":"","name":"list_key_value"},{"description":"","name":"list_log_label_values"},{"description":"","name":"list_logs"},{"description":"","name":"list_postgres_instances"},{"description":"","name":"list_services"},{"description":"","name":"list_workspaces"},{"description":"","name":"query_render_postgres"},{"description":"","name":"select_workspace"},{"description":"","name":"trigger_deploy","risk":{"category":"code_execution","level":"high","recommendation":"Block in production. If needed, scope tightly to a sandboxed account and require explicit approval.","why":"Runs arbitrary code, queries, shell commands, or deployment actions with the privileges granted to the connector."}},{"description":"","name":"update_cron_job","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"","name":"update_environment_variables","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"","name":"update_static_site","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"","name":"update_web_service","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}}],"tools_count":25,"type":"web_connector","url":"https://claude.ai/directory/045e9791-ed0d-4dfb-8271-a2f1ff62f9f0","uuid":"1fab8f76-695c-5562-bd7a-4604f8aec53c","version":""},"query_key":"render render","schema_version":1,"status":"match"}
