Runn Mcp Server — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Runn Mcp Server (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Standalone MCP server for the Runn API with simple reporting helpers.
RUNN_API_KEY)python3 -m venv .venv
source .venv/bin/activate
python -m pip install --upgrade pip
pip install -r requirements.txtpy -m venv .venv
.\\.venv\\Scripts\\Activate.ps1
py -m pip install --upgrade pip
pip install -r requirements.txtpy -m venv .venv
.\\.venv\\Scripts\\activate.bat
py -m pip install --upgrade pip
pip install -r requirements.txtbrew install [email protected]
python3 -m venv .venv
source .venv/bin/activate
python -m pip install --upgrade pip
pip install -r requirements.txtRUNN_API_KEY=LIVE_... python3 mcp_runn_server.py --transport stdio$env:RUNN_API_KEY="LIVE_..."
py mcp_runn_server.py --transport stdioRUNN_API_KEY=LIVE_... python3 mcp_runn_server.py --transport stdioRUNN_API_KEY=LIVE_... python3 mcp_runn_server.py --transport streamable-http$env:RUNN_API_KEY="LIVE_..."
py mcp_runn_server.py --transport streamable-httpRUNN_API_KEY=LIVE_... python3 mcp_runn_server.py --transport streamable-httpBuild the image:
docker build -t runn-mcp-server .docker build -t runn-mcp-server .Run the container (HTTP transport):
docker run --rm -e RUNN_API_KEY=LIVE_... -p 8000:8000 runn-mcp-serverdocker run --rm -e RUNN_API_KEY=LIVE_... -p 8000:8000 runn-mcp-serverdocker run --rm -e RUNN_API_KEY=LIVE_... -p 8000:8000 runn-mcp-serverThe GitHub Actions workflow publishes to:
ghcr.io/gemini2026/runn-mcp-serverPull and run:
docker pull ghcr.io/gemini2026/runn-mcp-server:main
docker run --rm -e RUNN_API_KEY=LIVE_... -p 8000:8000 ghcr.io/gemini2026/runn-mcp-server:maindocker pull ghcr.io/gemini2026/runn-mcp-server:main
docker run --rm -e RUNN_API_KEY=LIVE_... -p 8000:8000 ghcr.io/gemini2026/runn-mcp-server:maindocker pull ghcr.io/gemini2026/runn-mcp-server:main
docker run --rm -e RUNN_API_KEY=LIVE_... -p 8000:8000 ghcr.io/gemini2026/runn-mcp-server:main{
"mcpServers": {
"runn": {
"command": "/path/to/python3",
"args": [
"/path/to/mcp_runn_server.py",
"--transport",
"stdio"
],
"env": {
"RUNN_API_KEY": "<YOUR_API_KEY>"
}
}
}
}{
"mcpServers": {
"runn": {
"command": "C:\\\\Python311\\\\python.exe",
"args": [
"C:\\\\path\\\\to\\\\mcp_runn_server.py",
"--transport",
"stdio"
],
"env": {
"RUNN_API_KEY": "<YOUR_API_KEY>"
}
}
}
}list_projects — returns {id, name} pairs.list_people — returns {id, name, email} by default (set full=true for raw objects).billable_hours — aggregates billable hours grouped by project/person/month.list_clients — list clients (raw API objects).list_assignments — list assignments (raw API objects).list_assignments_by_person — assignments for a person, optional date range.list_assignments_by_project — assignments for a project, optional date range.list_assignments_by_role — assignments for a role, optional date range.list_assignments_by_team — assignments for a team’s people, optional date range.list_actuals — list actuals (raw API objects).list_actuals_by_date_range — actuals in a date range, optional person/project filters.list_actuals_by_person — actuals for a person, optional date range.list_actuals_by_project — actuals for a project, optional date range.list_actuals_by_role — actuals for a role, optional date range.list_actuals_by_team — actuals for a team’s people, optional date range.list_roles — list roles (raw API objects).list_roles_by_person — roles that include a person.list_skills — list skills (raw API objects).list_skills_by_person — skills for a person with levels + names.list_teams — list teams (raw API objects).list_people_by_team — people in a team (optionally include archived).list_people_by_skill — people who have a skill (optional min level).list_people_by_tag — people with a tag (by id or name).list_people_by_manager — people managed by a manager id.list_rate_cards — list rate cards (raw API objects).list_rate_cards_by_project — rate cards that include a project.runn_request — call any Runn API endpoint (GET/POST/PATCH/PUT/DELETE).Pagination for list endpoints:
{
"method": "GET",
"path": "/projects",
"paginate": true
}Filter-specific tools (e.g., list_assignments_by_person) fetch list endpoints and apply filters client-side.
RUNN_API_KEY=LIVE_... python3 mcp_runn_server.py --transport streamable-http curl -s http://localhost:8000/api \
-H "Content-Type: application/json" \
-d '{
"tool": "list_actuals_by_person",
"args": {
"person_id": 123,
"start": "2025-01-01",
"end": "2025-01-31"
}
}' | jq curl -s http://localhost:8000/api \
-H "Content-Type: application/json" \
-d '{
"tool": "runn_request",
"args": {
"method": "GET",
"path": "/projects"
}
}' | jqprintf '{"tool":"list_projects"}' | RUNN_API_KEY=LIVE_... python3 mcp_runn_server.py --transport stdioClaude will read the JSON response from stdout, just like any MCP client.
docker run --rm -e RUNN_API_KEY=LIVE_... -p 8000:8000 runn-mcp-serverConnect via the HTTP examples above or switch to stdio by appending --transport stdio on the Docker command.
runn_reports.py can export billable hours grouped by project/person/month.
RUNN_API_KEY=LIVE_... python3 runn_reports.py --start 2025-01-01 --end 2025-12-31 --output billable.csvPDF output requires ReportLab:
python -m pip install reportlabmain.v0.1.0.Example release:
git tag v0.1.0
git push origin v0.1.0~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.