{"generated_at":"2026-09-18T12:54:00+00:00","item":{"added_at":"2026-08-04T00:19:31.195000+00:00","analysis_method":"capability_triage","category":"Desktop Extension","description":"Connect Claude to Litmus Edge industrial devices through your Litmus MCP Server.","did":"ant-dir-gh-litmusautomation-litmus-mcp-server","homepage_url":"","icon":"https://claude.ai/api/dxt/extensions/ant.dir.gh.litmusautomation.litmus-mcp-server/versions/1.4.0/icon.png","id":"ant.dir.gh.litmusautomation.litmus-mcp-server","installs":0,"last_scanned":"","license":"","long_description":"Gives Claude access to your Litmus Edge deployment: browse DeviceHub devices and tags, read real-time and historical process data, manage Digital Twins, inspect system health, and reach the full Litmus SDK surface. This extension bridges Claude Desktop to a Litmus MCP Server you run on your own network (see https://github.com/litmusautomation/litmus-mcp-server); your credentials are stored in the operating system keychain and sent only to that server.","name":"Litmus MCP","plutonium_url":"https://plutonium.pluto.security/detail.html?planet=claudesec&did=ant-dir-gh-litmusautomation-litmus-mcp-server&utm_source=plutonium_analysis_skill&utm_medium=claude_skill&utm_campaign=connector_risk_assessment","publisher":"","publisher_url":"","repository_url":"","risk":"medium","risk_severity":"medium","security_risks":[{"description":"This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.","evidence":"The zero-tool snapshot still declares private process-data reads, Digital Twin management, and credentials stored persistently in the OS keychain.","remediation":{"block_tool_categories":["state_change"],"steps":["Try the connector on a test account first to see what it changes before letting it touch your real records.","Where the connected service supports it, give Claude read-only access and only allow writes for the specific things you need updated.","In the tools list below, turn off any tool you don't actively need - the ones tagged Block are the most important to disable."]},"risk_type":"modifies_data","severity":"medium","title":"Can change or update your information"},{"description":"Using the connector typically involves stored authorization to AppFolio/Realm-X so Claude can act across sessions, creating exposure if tokens are mishandled.","evidence":"The zero-tool snapshot still declares private process-data reads, Digital Twin management, and credentials stored persistently in the OS keychain.","remediation":{"block_tool_categories":[],"steps":["Keep the connector's API keys in a password manager - not in plain-text notes, email, or anywhere shared.","Replace the keys every few months, and immediately if a laptop is lost or someone leaves the team.","Generate keys with the smallest amount of access the connector needs; don't reuse a key that grants full account control."]},"risk_type":"requires_persistent_credentials","severity":"medium","title":"Stores long-lived access tokens"},{"description":"This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.","evidence":"The zero-tool snapshot still declares private process-data reads, Digital Twin management, and credentials stored persistently in the OS keychain.","remediation":{"block_tool_categories":[],"steps":["Connect using an account that only has access to the information you actually want Claude to read - not your main admin login.","When you grant access, pick the smallest set of folders, mailboxes, or channels possible.","Check the connector's activity log every so often to make sure nothing unexpected is being read."]},"risk_type":"reads_private_data","severity":"low","title":"Reads your private information"}],"signature_status":"unknown","source_code_reviewed":false,"tags":["desktop_extension","modifies_data","network_access","reads_private_data","requires_persistent_credentials"],"tools":[],"tools_count":0,"type":"desktop_extension","url":"","uuid":"b436f798-3800-5b5e-ab50-e5e94656a242","version":"1.4.0"},"query_key":"litmus mcp","schema_version":1,"status":"match"}
