{"generated_at":"2026-08-17T10:36:11+00:00","item":{"added_at":"2026-04-04","analysis_method":"capability_triage","category":"Web Connector","description":"Manage your full incident.io workspace from one place. Declare and triage incidents, ack pages, check who's on call, and track follow-ups - without switching...","did":"io-incident-mcp","homepage_url":"","icon":"https://incident.io/apple-touch-icon.png","id":"io.incident/mcp","installs":0,"last_scanned":"","license":"","long_description":"Manage your full incident.io workspace from one place. Declare and triage incidents, ack pages, check who's on call, and track follow-ups - without switching tools. Analyze incident trends, escalation response rates, and alert noise across your organization. Browse your catalog, query telemetry from connected observability tools, and run structured operational reviews. Everything your team needs to stay on top of things, without the tab juggling.","name":"incident.io","plutonium_url":"https://plutonium.pluto.security/detail.html?planet=claudesec&did=io-incident-mcp&utm_source=plutonium_analysis_skill&utm_medium=claude_skill&utm_campaign=connector_risk_assessment","publisher":"incident.io","publisher_url":"https://incident.io","repository_url":"","risk":"medium","risk_severity":"medium","security_risks":[{"description":"This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.","evidence":"Connector has 35 tools; permissions on claude.ai/directory: \"Read + Write\". Data flows out of the connected service into the model.","remediation":{"block_tool_categories":[],"steps":["Connect using an account that only has access to the information you actually want Claude to read - not your main admin login.","When you grant access, pick the smallest set of folders, mailboxes, or channels possible.","Check the connector's activity log every so often to make sure nothing unexpected is being read."]},"risk_type":"reads_private_data","severity":"medium","title":"Reads your private information"},{"description":"This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.","evidence":"6 state change tools on this connector - e.g. follow_up_create, follow_up_update, incident_create, incident_update and 2 more.","remediation":{"block_tool_categories":["state_change"],"steps":["Try the connector on a test account first to see what it changes before letting it touch your real records.","Where the connected service supports it, give Claude read-only access and only allow writes for the specific things you need updated.","In the tools list below, turn off any tool you don't actively need - the ones tagged Block are the most important to disable."]},"risk_type":"modifies_data","severity":"medium","title":"Can change or update your information"},{"description":"Anything you share with this connector flows through one or more third-party services. Those companies see, store, and may use the data according to their own policies.","evidence":"Server runs at mcp.incident.io/mcp; queries and responses pass through the publisher's infrastructure.","remediation":{"block_tool_categories":[],"steps":["Treat anything you tell this connector as if you sent it directly to the third-party company - because you did.","Check how long that company keeps your data and how to delete it.","Avoid putting health info, customer names, or payment details into this connector unless you have a written agreement with that company."]},"risk_type":"forwards_data_to_third_party","severity":"low","title":"Sends your data to outside companies"}],"signature_status":"unknown","source_code_reviewed":false,"tags":["network_access","reads_private_data","database_access"],"tools":[{"description":"Search and browse alerts.","name":"alert_list"},{"description":"Returns full alert details with linked incidents.","name":"alert_show"},{"description":"Lists configured alert sources.","name":"alert_source_list"},{"description":"Returns alert counts with workload from linked incidents.","name":"alert_stats"},{"description":"Starts a structured operational analysis with playbooks and report template.","name":"analysis_start"},{"description":"AI agent for on-call queries, schedule management, and general questions.","name":"ask"},{"description":"AI agent for incident investigation and management actions.","name":"ask_incident"},{"description":"AI agent for querying logs, metrics, traces, and dashboards.","name":"ask_telemetry"},{"description":"Browses entries in a catalog type.","name":"catalog_entry_list"},{"description":"Returns full catalog entry with all attributes.","name":"catalog_entry_show"},{"description":"Lists catalog types such as Service and Team.","name":"catalog_type_list"},{"description":"Searches escalations (pages).","name":"escalation_list"},{"description":"Lists escalation paths.","name":"escalation_path_list"},{"description":"Shows who would be paged at each escalation level.","name":"escalation_path_show"},{"description":"Acknowledges or declines a page.","name":"escalation_respond"},{"description":"Returns full escalation details with transition history.","name":"escalation_show"},{"description":"Returns paging counts by path, priority, and time of day.","name":"escalation_stats"},{"description":"Submits feedback about the tools.","name":"feedback"},{"description":"Creates a follow-up on an incident.","name":"follow_up_create","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"Lists post-incident follow-ups.","name":"follow_up_list"},{"description":"","name":"follow_up_stats"},{"description":"","name":"follow_up_update","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"Creates a new incident.","name":"incident_create","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"Searches and browses incidents with filters, sortable by workload.","name":"incident_list"},{"description":"Returns full incident details with optional investigation, post-mortem, and update history.","name":"incident_show"},{"description":"Returns aggregate counts and workload by 10+ dimensions.","name":"incident_stats"},{"description":"Updates incident fields such as status, severity, roles, and custom fields.","name":"incident_update","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"Returns full status update history for an incident.","name":"incident_update_list","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"Downloads a full investigation as an archive for LLM analysis.","name":"investigation_sync","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"","name":"resource_list"},{"description":"Reads organisation config, analysis playbooks, or telemetry datasources.","name":"resource_show"},{"description":"Lists on-call schedules.","name":"schedule_list"},{"description":"Returns schedule details with current and upcoming shifts.","name":"schedule_show"},{"description":"Lists teams.","name":"team_list"},{"description":"Returns team details with owned escalation paths, alert sources, and schedules.","name":"team_show"}],"tools_count":35,"type":"web_connector","url":"https://claude.ai/directory/1f80285c-87b3-496f-91b3-07ea8fc86488","uuid":"0befebe7-4d25-53bf-bb60-e9bbf2f5d1eb","version":""},"query_key":"incident io","schema_version":1,"status":"match"}
