{"generated_at":"2026-08-08T12:20:51+00:00","item":{"added_at":"2026-03-16","analysis_method":"capability_triage","category":"Web Connector","description":"Jentic connects Claude to 1,500+ APIs through a single MCP server. Credentials never touch your prompts - Jentic's managed vault handles auth centrally. Just...","did":"com-jentic-jentic","homepage_url":"","icon":"https://jentic.com/apple-touch-icon.png","id":"com.jentic/jentic","installs":0,"last_scanned":"","license":"","long_description":"Jentic connects Claude to 1,500+ APIs through a single MCP server. Credentials never touch your prompts - Jentic's managed vault handles auth centrally. Just-In-Time Tooling means agents fetch only the tools they need, keeping context lean and reasoning accurate.","name":"Jentic","plutonium_url":"https://plutonium.pluto.security/detail.html?planet=claudesec&did=com-jentic-jentic&utm_source=plutonium_analysis_skill&utm_medium=claude_skill&utm_campaign=connector_risk_assessment","publisher":"Jentic","publisher_url":"https://jentic.com/","repository_url":"","risk":"high","risk_severity":"high","security_risks":[{"description":"This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.","evidence":"Connector has 3 tools; permissions on claude.ai/directory: \"Read and write\". Data flows out of the connected service into the model.","remediation":{"block_tool_categories":[],"steps":["Connect using an account that only has access to the information you actually want Claude to read - not your main admin login.","When you grant access, pick the smallest set of folders, mailboxes, or channels possible.","Check the connector's activity log every so often to make sure nothing unexpected is being read."]},"risk_type":"reads_private_data","severity":"medium","title":"Reads your private information"},{"description":"This connector can execute scripts, shell commands, or arbitrary database queries. In a worst case, an attacker could install software, read files, or pull or change any data its login can reach.","evidence":"1 code execution tool on this connector - e.g. execute.","remediation":{"block_tool_categories":["code_execution"],"steps":["In the tools list below, turn off any tool tagged Block before connecting this to real data or production systems.","If you need code execution, run it on a separate test machine that has no access to your work files, customer data, or saved passwords.","Limit which websites and services that test machine can talk to."]},"risk_type":"runs_code","severity":"high","title":"Can run commands or queries on your behalf"},{"description":"Anything you share with this connector flows through one or more third-party services. Those companies see, store, and may use the data according to their own policies.","evidence":"Server runs at api.jentic.com/mcp; queries and responses pass through the publisher's infrastructure.","remediation":{"block_tool_categories":[],"steps":["Treat anything you tell this connector as if you sent it directly to the third-party company - because you did.","Check how long that company keeps your data and how to delete it.","Avoid putting health info, customer names, or payment details into this connector unless you have a written agreement with that company."]},"risk_type":"forwards_data_to_third_party","severity":"low","title":"Sends your data to outside companies"}],"signature_status":"unknown","source_code_reviewed":false,"tags":["network_access","reads_private_data","shell_access"],"tools":[{"description":"Searches thousands of available API operations and workflows using natural language queries to find matching APIs.","name":"search_apis"},{"description":"Loads detailed metadata for a selected API operation, including required inputs and usage information.","name":"load_execution_info"},{"description":"Executes a specified API operation with provided inputs and returns results directly in the chat.","name":"execute","risk":{"category":"code_execution","level":"high","recommendation":"Block in production. If needed, scope tightly to a sandboxed account and disallow shell/SQL passthrough.","why":"Runs arbitrary code, queries, or shell commands. Effectively grants the model the same privileges as the configured account on the target system."}}],"tools_count":3,"type":"web_connector","url":"https://claude.ai/directory/a133f422-ff03-478f-a208-ddc460db8826","uuid":"560b1e96-50b5-5baf-9b9d-f4bd7251da02","version":""},"query_key":"jentic","schema_version":1,"status":"match"}
