Claude security directory

Render

Published by Render

High risk

Render's official MCP server lets AI apps and agents manage your Render infrastructure through natural language. Create and deploy web services, static sites, and cron jobs; provision Render Postgres and Key Value instances; trigger and inspect deploys; update environment variables and compute plans; stream logs; analyze performance metrics; and run read-only SQL against your Postgres — all scoped to a workspace you choose. Hosted by Render at https://mcp.render.com/mcp, it connects over OAuth (or a Render API key) and is designed to keep secrets like connection strings out of your AI app's context.

Security assessment

Plutonium assessed this web connector for permissions, capabilities, and security-relevant behavior.

  • Can run commands or queries on your behalf: This connector can execute scripts, shell commands, or arbitrary database queries. In a worst case, an attacker could install software, read files, or pull or change any data its login can reach.
  • Can change or update your information: This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.
  • Reads your private information: This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.
  • Sends your data to outside companies: Anything you share with this connector flows through one or more third-party services. Those companies see, store, and may use the data according to their own policies.

Available capabilities

This add-on exposes 25 tools or capabilities.

  • create_cron_job
  • create_key_value
  • create_postgres
  • create_static_site
  • create_web_service
  • get_deploy
  • get_key_value
  • get_metrics
  • get_postgres
  • get_selected_workspace
  • get_service
  • list_deploys
  • list_key_value
  • list_log_label_values
  • list_logs
  • list_postgres_instances
  • list_services
  • list_workspaces
  • query_render_postgres
  • select_workspace
  • trigger_deploy
  • update_cron_job
  • update_environment_variables
  • update_static_site

The interactive security report will load automatically.