{"generated_at":"2026-08-17T10:36:11+00:00","item":{"added_at":"2026-03-31T21:00:35.751000+00:00","analysis_method":"capability_triage","category":"Desktop Extension","description":"Complete agent stack for Jaz accounting.\n\n247 tools: invoices, bills, credit notes, journals, cash entries, contacts, items, chart of accounts, bank reco...","did":"ant-dir-gh-teamtinvio-jaz-ai","homepage_url":"","icon":"https://claude.ai/api/dxt/extensions/ant.dir.gh.teamtinvio.jaz-ai/versions/4.55.6/icon.png","id":"ant.dir.gh.teamtinvio.jaz-ai","installs":3829,"last_scanned":"","license":"MIT","long_description":"Complete agent stack for Jaz accounting.\n\n247 tools: invoices, bills, credit notes, journals, cash entries, contacts, items, chart of accounts, bank reconciliation, reports, attachments, payments, currency management, and more.\n\n13 financial calculators: loan amortization, depreciation (SL/DDB/SYD), IFRS 16 leases, hire purchase, fixed deposits, asset disposal, FX revaluation, ECL provisioning, IAS 37 provisions, prepaid amortization. Each outputs journal entries, ...","name":"Jaz Accounting","plutonium_url":"https://plutonium.pluto.security/detail.html?planet=claudesec&did=ant-dir-gh-teamtinvio-jaz-ai&utm_source=plutonium_analysis_skill&utm_medium=claude_skill&utm_campaign=connector_risk_assessment","publisher":"Jaz Engineering","publisher_url":"https://jaz.ai","repository_url":"https://github.com/teamtinvio/jaz-ai.git","risk":"high","risk_severity":"high","security_risks":[{"description":"This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.","evidence":"Connector has 247 tools; permissions on claude.ai/directory: \"unknown\". Data flows out of the connected service into the model.","remediation":{"block_tool_categories":[],"steps":["Connect using an account that only has access to the information you actually want Claude to read - not your main admin login.","When you grant access, pick the smallest set of folders, mailboxes, or channels possible.","Check the connector's activity log every so often to make sure nothing unexpected is being read."]},"risk_type":"reads_private_data","severity":"medium","title":"Reads your private information"},{"description":"This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.","evidence":"89 state change tools on this connector - e.g. create_account, update_account, create_contact, update_contact and 85 more.","remediation":{"block_tool_categories":["state_change"],"steps":["Try the connector on a test account first to see what it changes before letting it touch your real records.","Where the connected service supports it, give Claude read-only access and only allow writes for the specific things you need updated.","In the tools list below, turn off any tool you don't actively need - the ones tagged Block are the most important to disable."]},"risk_type":"modifies_data","severity":"medium","title":"Can change or update your information"},{"description":"This connector can complete purchases, bookings, or payments. A misused or hijacked prompt could result in real financial charges before you confirm.","evidence":"13 financial tools on this connector - e.g. get_invoice, pay_invoice, finalize_invoice, download_invoice_pdf and 9 more.","remediation":{"block_tool_categories":["financial"],"steps":["In the tools list below, turn off any tool tagged Block by default; only enable them when you actually want Claude to make a purchase.","Set a spending limit on the linked credit card, billing account, or virtual card so a mistake can't cost you much.","Always confirm in the chat before Claude completes a payment or books anything."]},"risk_type":"spends_money","severity":"high","title":"Can spend money on your behalf"},{"description":"This connector can erase records, files, or accounts. Once deleted the data may be unrecoverable - even an accidental request can cause permanent loss.","evidence":"26 destructive tools on this connector - e.g. delete_invoice, delete_bill, delete_journal, delete_item and 22 more.","remediation":{"block_tool_categories":["destructive"],"steps":["In the tools list below, turn off any tool tagged Block - most workflows don't need Claude to delete anything.","If you really do need deletion, use a login that doesn't have delete permission and have a person handle removals manually.","Make sure the connected service has a trash / recycle bin enabled so accidental deletes can be recovered."]},"risk_type":"deletes_data","severity":"high","title":"Can permanently delete data"},{"description":"This connector can execute scripts, shell commands, or arbitrary database queries. In a worst case, an attacker could install software, read files, or pull or change any data its login can reach.","evidence":"3 code execution tools on this connector - e.g. apply_credits_to_invoice, apply_credits_to_bill, execute_recipe.","remediation":{"block_tool_categories":["code_execution"],"steps":["In the tools list below, turn off any tool tagged Block before connecting this to real data or production systems.","If you need code execution, run it on a separate test machine that has no access to your work files, customer data, or saved passwords.","Limit which websites and services that test machine can talk to."]},"risk_type":"runs_code","severity":"high","title":"Can run commands or queries on your behalf"},{"description":"This connector can post messages, emails, or chat replies on your behalf. Recipients will believe the message came from you, which makes phishing or social-engineering risks higher.","evidence":"1 sends externally tool on this connector - e.g. message_to_pdf.","remediation":{"block_tool_categories":["sends_externally"],"steps":["In the tools list below, turn off any tool tagged Block if you don't need Claude to send messages or emails on your behalf.","If you do enable sending, restrict it to a private channel or distribution list - never customer-facing or company-wide.","Read the message before it goes out: don't let Claude send anything without you confirming first."]},"risk_type":"sends_messages_as_you","severity":"medium","title":"Can send messages as you"}],"signature_status":"unsigned","source_code_reviewed":true,"tags":["reads_private_data","database_access","financial_ops","deletes_data","filesystem_access","email_messaging","shell_access"],"tools":[{"description":"","name":"get_organization"},{"description":"","name":"list_accounts"},{"description":"","name":"search_accounts"},{"description":"","name":"create_account","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"","name":"update_account","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"","name":"list_contacts"},{"description":"","name":"search_contacts"},{"description":"","name":"get_contact"},{"description":"","name":"create_contact","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"","name":"update_contact","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"","name":"list_invoices"},{"description":"","name":"search_invoices"},{"description":"","name":"get_invoice","risk":{"category":"financial","level":"high","recommendation":"Block by default. Require human-in-the-loop confirmation for every transaction; do not allow autonomous execution.","why":"Initiates a financial transaction or paid action. A confused-deputy or prompt-injection scenario can spend money on the user's behalf."}},{"description":"","name":"create_invoice","risk":{"category":"financial","level":"high","recommendation":"Block by default. Require human-in-the-loop confirmation for every transaction; do not allow autonomous execution.","why":"Initiates a financial transaction or paid action. A confused-deputy or prompt-injection scenario can spend money on the user's behalf."}},{"description":"","name":"update_invoice","risk":{"category":"financial","level":"high","recommendation":"Block by default. Require human-in-the-loop confirmation for every transaction; do not allow autonomous execution.","why":"Initiates a financial transaction or paid action. A confused-deputy or prompt-injection scenario can spend money on the user's behalf."}},{"description":"","name":"delete_invoice","risk":{"category":"destructive","level":"high","recommendation":"Block by default. Only enable for read-only or sandbox accounts; require explicit human confirmation for any destructive action.","why":"Irreversibly removes data or resources. A prompt-injection or mistaken instruction could destroy production data with no recovery path."}},{"description":"","name":"pay_invoice","risk":{"category":"financial","level":"high","recommendation":"Block by default. Require human-in-the-loop confirmation for every transaction; do not allow autonomous execution.","why":"Initiates a financial transaction or paid action. A confused-deputy or prompt-injection scenario can spend money on the user's behalf."}},{"description":"","name":"finalize_invoice","risk":{"category":"financial","level":"high","recommendation":"Block by default. Require human-in-the-loop confirmation for every transaction; do not allow autonomous execution.","why":"Initiates a financial transaction or paid action. A confused-deputy or prompt-injection scenario can spend money on the user's behalf."}},{"description":"","name":"apply_credits_to_invoice","risk":{"category":"code_execution","level":"high","recommendation":"Block in production. If needed, scope tightly to a sandboxed account and disallow shell/SQL passthrough.","why":"Runs arbitrary code, queries, or shell commands. Effectively grants the model the same privileges as the configured account on the target system."}},{"description":"","name":"download_invoice_pdf","risk":{"category":"financial","level":"high","recommendation":"Block by default. Require human-in-the-loop confirmation for every transaction; do not allow autonomous execution.","why":"Initiates a financial transaction or paid action. A confused-deputy or prompt-injection scenario can spend money on the user's behalf."}},{"description":"","name":"list_bills"},{"description":"","name":"search_bills"},{"description":"","name":"get_bill"},{"description":"","name":"create_bill","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"","name":"update_bill","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"","name":"delete_bill","risk":{"category":"destructive","level":"high","recommendation":"Block by default. Only enable for read-only or sandbox accounts; require explicit human confirmation for any destructive action.","why":"Irreversibly removes data or resources. A prompt-injection or mistaken instruction could destroy production data with no recovery path."}},{"description":"","name":"pay_bill","risk":{"category":"financial","level":"high","recommendation":"Block by default. Require human-in-the-loop confirmation for every transaction; do not allow autonomous execution.","why":"Initiates a financial transaction or paid action. A confused-deputy or prompt-injection scenario can spend money on the user's behalf."}},{"description":"","name":"finalize_bill"},{"description":"","name":"apply_credits_to_bill","risk":{"category":"code_execution","level":"high","recommendation":"Block in production. If needed, scope tightly to a sandboxed account and disallow shell/SQL passthrough.","why":"Runs arbitrary code, queries, or shell commands. Effectively grants the model the same privileges as the configured account on the target system."}},{"description":"","name":"list_journals"},{"description":"","name":"get_journal"},{"description":"","name":"search_journals"},{"description":"","name":"create_journal","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"","name":"create_transfer_trial_balance","risk":{"category":"financial","level":"high","recommendation":"Block by default. Require human-in-the-loop confirmation for every transaction; do not allow autonomous execution.","why":"Initiates a financial transaction or paid action. A confused-deputy or prompt-injection scenario can spend money on the user's behalf."}},{"description":"","name":"delete_journal","risk":{"category":"destructive","level":"high","recommendation":"Block by default. Only enable for read-only or sandbox accounts; require explicit human confirmation for any destructive action.","why":"Irreversibly removes data or resources. A prompt-injection or mistaken instruction could destroy production data with no recovery path."}},{"description":"","name":"generate_trial_balance","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"","name":"generate_balance_sheet","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"","name":"generate_profit_and_loss","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"","name":"generate_cashflow","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"","name":"generate_aged_ar","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"","name":"generate_aged_ap","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"","name":"generate_cash_balance","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"","name":"generate_general_ledger","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"","name":"list_bank_accounts"},{"description":"","name":"list_items"},{"description":"","name":"search_items"},{"description":"","name":"get_item"},{"description":"","name":"create_item","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"","name":"update_item","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"","name":"delete_item","risk":{"category":"destructive","level":"high","recommendation":"Block by default. Only enable for read-only or sandbox accounts; require explicit human confirmation for any destructive action.","why":"Irreversibly removes data or resources. A prompt-injection or mistaken instruction could destroy production data with no recovery path."}},{"description":"","name":"bulk_upsert_items"},{"description":"","name":"list_tags"},{"description":"","name":"search_tags"},{"description":"","name":"create_tag","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"","name":"get_tag","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"","name":"update_tag","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"","name":"delete_tag","risk":{"category":"destructive","level":"high","recommendation":"Block by default. Only enable for read-only or sandbox accounts; require explicit human confirmation for any destructive action.","why":"Irreversibly removes data or resources. A prompt-injection or mistaken instruction could destroy production data with no recovery path."}},{"description":"","name":"list_capsule_types"},{"description":"","name":"list_capsules"},{"description":"","name":"search_capsules"},{"description":"","name":"get_capsule"},{"description":"","name":"create_capsule","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"","name":"update_capsule","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"","name":"delete_capsule","risk":{"category":"destructive","level":"high","recommendation":"Block by default. Only enable for read-only or sandbox accounts; require explicit human confirmation for any destructive action.","why":"Irreversibly removes data or resources. A prompt-injection or mistaken instruction could destroy production data with no recovery path."}},{"description":"","name":"list_customer_credit_notes"},{"description":"","name":"search_customer_credit_notes"},{"description":"","name":"get_customer_credit_note"},{"description":"","name":"create_customer_credit_note","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"","name":"delete_customer_credit_note","risk":{"category":"destructive","level":"high","recommendation":"Block by default. Only enable for read-only or sandbox accounts; require explicit human confirmation for any destructive action.","why":"Irreversibly removes data or resources. A prompt-injection or mistaken instruction could destroy production data with no recovery path."}},{"description":"","name":"update_customer_credit_note","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"","name":"finalize_customer_credit_note"},{"description":"","name":"create_customer_credit_note_refund","risk":{"category":"financial","level":"high","recommendation":"Block by default. Require human-in-the-loop confirmation for every transaction; do not allow autonomous execution.","why":"Initiates a financial transaction or paid action. A confused-deputy or prompt-injection scenario can spend money on the user's behalf."}},{"description":"","name":"list_customer_credit_note_refunds"},{"description":"","name":"list_supplier_credit_notes"},{"description":"","name":"search_supplier_credit_notes"},{"description":"","name":"get_supplier_credit_note"},{"description":"","name":"create_supplier_credit_note","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"","name":"delete_supplier_credit_note","risk":{"category":"destructive","level":"high","recommendation":"Block by default. Only enable for read-only or sandbox accounts; require explicit human confirmation for any destructive action.","why":"Irreversibly removes data or resources. A prompt-injection or mistaken instruction could destroy production data with no recovery path."}},{"description":"","name":"update_supplier_credit_note","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"","name":"finalize_supplier_credit_note"}],"tools_count":247,"type":"desktop_extension","url":"","uuid":"fad5a2aa-c66b-59ef-8a0e-136784d947a0","version":"4.55.6"},"query_key":"jaz accounting","schema_version":1,"status":"match"}
