{"generated_at":"2026-09-18T12:54:00+00:00","item":{"added_at":"2026-08-13T19:02:44.176000+00:00","analysis_method":"capability_triage","category":"Desktop Extension","description":"Connect Claude Desktop to a Denodo Virtual DataPort database via MCP","did":"ant-dir-gh-denodo-denodocommunity-claude-vdp-connector","homepage_url":"","icon":"https://claude.ai/api/dxt/extensions/ant.dir.gh.denodo.denodocommunity-claude-vdp-connector/versions/1.3.2/icon.png","id":"ant.dir.gh.denodo.denodocommunity-claude-vdp-connector","installs":0,"last_scanned":"","license":"","long_description":"This extension connects Claude Desktop to a running Denodo MCP Server, enabling AI-powered querying of Denodo Virtual DataPort databases. Supports three authentication modes: (1) Basic Auth with username and password; (2) OAuth bearer token — paste a static JWT, optionally with automatic refresh via a refresh token grant; (3) OAuth Authorization Code flow — a browser window opens for you to log in, and the connector handles token refresh silently from then on (uses PKCE for public clients). Requires a Denodo MCP Server (v9, build 20260317 or later) running and accessible.","name":"Denodo MCP Connector","plutonium_url":"https://plutonium.pluto.security/detail.html?planet=claudesec&did=ant-dir-gh-denodo-denodocommunity-claude-vdp-connector&utm_source=plutonium_analysis_skill&utm_medium=claude_skill&utm_campaign=connector_risk_assessment","publisher":"","publisher_url":"","repository_url":"","risk":"high","risk_severity":"high","security_risks":[{"description":"This connector can execute scripts, shell commands, or arbitrary database queries. In a worst case, an attacker could install software, read files, or pull or change any data its login can reach.","evidence":"1 observed tool(s): run_vql_query.","remediation":{"block_tool_categories":["code_execution"],"steps":["In the tools list below, turn off any tool tagged Block before connecting this to real data or production systems.","If you need code execution, run it on a separate test machine that has no access to your work files, customer data, or saved passwords.","Limit which websites and services that test machine can talk to."]},"risk_type":"runs_code","severity":"high","title":"Can run commands or queries on your behalf"},{"description":"This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.","evidence":"Kept High; unrestricted VQL execution is a code/query High gate and can read private connected database data.","remediation":{"block_tool_categories":[],"steps":["Connect using an account that only has access to the information you actually want Claude to read - not your main admin login.","When you grant access, pick the smallest set of folders, mailboxes, or channels possible.","Check the connector's activity log every so often to make sure nothing unexpected is being read."]},"risk_type":"reads_private_data","severity":"low","title":"Reads your private information"}],"signature_status":"unknown","source_code_reviewed":false,"tags":["database_access","desktop_extension","network_access","reads_private_data","runs_code"],"tools":[{"description":"","name":"get_database_schema"},{"description":"","name":"get_view_names"},{"description":"","name":"get_view_schema"},{"description":"","name":"run_vql_query","risk":{"category":"code_execution","level":"high","recommendation":"Block in production. If needed, scope tightly to a sandboxed account and require explicit approval.","why":"Runs arbitrary code, queries, shell commands, or deployment actions with the privileges granted to the connector."}},{"description":"","name":"validate_vql_query"},{"description":"","name":"<database_name>_query_<tagged_view_name>"}],"tools_count":6,"type":"desktop_extension","url":"","uuid":"b6fe8f7b-7b49-57db-8aea-d016ca8fce09","version":"1.3.2"},"query_key":"denodo mcp connector","schema_version":1,"status":"match"}
