{"generated_at":"2026-08-17T10:36:11+00:00","item":{"added_at":"2026-03-06","analysis_method":"capability_triage","category":"Web Connector","description":"Manage incidents, create services, schedule overrides, and track on-call rotations with your PagerDuty account","did":"com-pagerduty-mcp","homepage_url":"","icon":"https://www.pagerduty.com/favicon.ico","id":"com.pagerduty/mcp","installs":0,"last_scanned":"","license":"","long_description":"Manage incidents, create services, schedule overrides, and track on-call rotations with your PagerDuty account","name":"PagerDuty","plutonium_url":"https://plutonium.pluto.security/detail.html?planet=claudesec&did=com-pagerduty-mcp&utm_source=plutonium_analysis_skill&utm_medium=claude_skill&utm_campaign=connector_risk_assessment","publisher":"PagerDuty","publisher_url":"https://www.pagerduty.com","repository_url":"","risk":"high","risk_severity":"high","security_risks":[{"description":"This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.","evidence":"Connector has 64 tools; permissions on claude.ai/directory: \"Read and write\". Data flows out of the connected service into the model.","remediation":{"block_tool_categories":[],"steps":["Connect using an account that only has access to the information you actually want Claude to read - not your main admin login.","When you grant access, pick the smallest set of folders, mailboxes, or channels possible.","Check the connector's activity log every so often to make sure nothing unexpected is being read."]},"risk_type":"reads_private_data","severity":"medium","title":"Reads your private information"},{"description":"This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.","evidence":"17 state change tools on this connector - e.g. add_note_to_incident, add_responders, add_team_member, create_alert_grouping_setting and 13 more.","remediation":{"block_tool_categories":["state_change"],"steps":["Try the connector on a test account first to see what it changes before letting it touch your real records.","Where the connected service supports it, give Claude read-only access and only allow writes for the specific things you need updated.","In the tools list below, turn off any tool you don't actively need - the ones tagged Block are the most important to disable."]},"risk_type":"modifies_data","severity":"medium","title":"Can change or update your information"},{"description":"This connector can erase records, files, or accounts. Once deleted the data may be unrecoverable - even an accidental request can cause permanent loss.","evidence":"3 destructive tools on this connector - e.g. delete_alert_grouping_setting, delete_team, remove_team_member.","remediation":{"block_tool_categories":["destructive"],"steps":["In the tools list below, turn off any tool tagged Block - most workflows don't need Claude to delete anything.","If you really do need deletion, use a login that doesn't have delete permission and have a person handle removals manually.","Make sure the connected service has a trash / recycle bin enabled so accidental deletes can be recovered."]},"risk_type":"deletes_data","severity":"high","title":"Can permanently delete data"},{"description":"This connector can post messages, emails, or chat replies on your behalf. Recipients will believe the message came from you, which makes phishing or social-engineering risks higher.","evidence":"2 sends externally tools on this connector - e.g. get_status_page_post, list_status_page_post_updates.","remediation":{"block_tool_categories":["sends_externally"],"steps":["In the tools list below, turn off any tool tagged Block if you don't need Claude to send messages or emails on your behalf.","If you do enable sending, restrict it to a private channel or distribution list - never customer-facing or company-wide.","Read the message before it goes out: don't let Claude send anything without you confirming first."]},"risk_type":"sends_messages_as_you","severity":"medium","title":"Can send messages as you"},{"description":"Anything you share with this connector flows through one or more third-party services. Those companies see, store, and may use the data according to their own policies.","evidence":"Server runs at mcp.pagerduty.com/mcp; queries and responses pass through the publisher's infrastructure.","remediation":{"block_tool_categories":[],"steps":["Treat anything you tell this connector as if you sent it directly to the third-party company - because you did.","Check how long that company keeps your data and how to delete it.","Avoid putting health info, customer names, or payment details into this connector unless you have a written agreement with that company."]},"risk_type":"forwards_data_to_third_party","severity":"low","title":"Sends your data to outside companies"}],"signature_status":"unknown","source_code_reviewed":false,"tags":["network_access","reads_private_data","browser_control","email_messaging","database_access","deletes_data"],"tools":[{"description":"Adds a note to an incident.","name":"add_note_to_incident","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"Adds responders to an incident.","name":"add_responders","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"Adds a user to a team with a specific role.","name":"add_team_member","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"Adds a new routing rule to an event orchestration router.","name":"append_event_orchestration_router_rule"},{"description":"Creates a new alert grouping setting.","name":"create_alert_grouping_setting","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"Creates a new incident.","name":"create_incident","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"Creates a new on-call schedule.","name":"create_schedule","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"Creates an override for a schedule.","name":"create_schedule_override","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"Creates a new service.","name":"create_service","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"Creates a new post (incident or maintenance) on a status page.","name":"create_status_page_post","risk":{"category":"sends_externally","level":"medium","recommendation":"Restrict to specific channels; require confirmation before sending. Disable if the connector is used in untrusted contexts.","why":"Sends a message or post on the user's behalf to people or channels outside the conversation. Phishing, leaking secrets, or impersonation become possible if the tool is hijacked."}},{"description":"Adds a new update to an existing status page post.","name":"create_status_page_post_update","risk":{"category":"sends_externally","level":"medium","recommendation":"Restrict to specific channels; require confirmation before sending. Disable if the connector is used in untrusted contexts.","why":"Sends a message or post on the user's behalf to people or channels outside the conversation. Phishing, leaking secrets, or impersonation become possible if the tool is hijacked."}},{"description":"Creates a new team.","name":"create_team","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"Deletes an alert grouping setting.","name":"delete_alert_grouping_setting","risk":{"category":"destructive","level":"high","recommendation":"Block by default. Only enable for read-only or sandbox accounts; require explicit human confirmation for any destructive action.","why":"Irreversibly removes data or resources. A prompt-injection or mistaken instruction could destroy production data with no recovery path."}},{"description":"Deletes a team.","name":"delete_team","risk":{"category":"destructive","level":"high","recommendation":"Block by default. Only enable for read-only or sandbox accounts; require explicit human confirmation for any destructive action.","why":"Irreversibly removes data or resources. A prompt-injection or mistaken instruction could destroy production data with no recovery path."}},{"description":"Retrieves a specific alert from an incident.","name":"get_alert_from_incident"},{"description":"Retrieves a specific alert grouping setting.","name":"get_alert_grouping_setting"},{"description":"Retrieves a specific change event.","name":"get_change_event"},{"description":"Retrieves a specific escalation policy.","name":"get_escalation_policy"},{"description":"Retrieves a specific event orchestration.","name":"get_event_orchestration"},{"description":"Gets the global orchestration configuration for an event orchestration.","name":"get_event_orchestration_global"},{"description":"Gets the router configuration for an event orchestration.","name":"get_event_orchestration_router"},{"description":"Gets the service orchestration configuration for a specific service.","name":"get_event_orchestration_service"},{"description":"Retrieves a specific incident.","name":"get_incident"},{"description":"Retrieves a specific incident workflow.","name":"get_incident_workflow"},{"description":"Retrieves a specific log entry by ID.","name":"get_log_entry"},{"description":"Retrieves outlier incident information for a specific incident.","name":"get_outlier_incident"},{"description":"Retrieves past incidents related to a specific incident.","name":"get_past_incidents"},{"description":"Retrieves related incidents for a specific incident.","name":"get_related_incidents"},{"description":"Retrieves a specific schedule.","name":"get_schedule"},{"description":"Retrieves a specific service.","name":"get_service"},{"description":"Retrieves details of a specific status page post.","name":"get_status_page_post","risk":{"category":"sends_externally","level":"medium","recommendation":"Restrict to specific channels; require confirmation before sending. Disable if the connector is used in untrusted contexts.","why":"Sends a message or post on the user's behalf to people or channels outside the conversation. Phishing, leaking secrets, or impersonation become possible if the tool is hijacked."}},{"description":"Retrieves a specific team.","name":"get_team"},{"description":"Gets the current user's data.","name":"get_user_data"},{"description":"Lists alert grouping settings with filtering.","name":"list_alert_grouping_settings"},{"description":"Lists all alerts for a specific incident with pagination.","name":"list_alerts_from_incident"},{"description":"Lists change events with optional filtering.","name":"list_change_events"},{"description":"Lists escalation policies.","name":"list_escalation_policies"},{"description":"Lists event orchestrations with optional filtering.","name":"list_event_orchestrations"},{"description":"Lists change events related to a specific incident.","name":"list_incident_change_events"},{"description":"Lists all notes for a specific incident.","name":"list_incident_notes"},{"description":"Lists incident workflows with optional filtering.","name":"list_incident_workflows"},{"description":"Lists incidents.","name":"list_incidents"},{"description":"Lists all log entries across the account with time filtering.","name":"list_log_entries"},{"description":"Lists on-call schedules.","name":"list_oncalls"},{"description":"Lists users in a schedule.","name":"list_schedule_users"},{"description":"Lists schedules.","name":"list_schedules"},{"description":"Lists change events for a specific service.","name":"list_service_change_events"},{"description":"Lists services.","name":"list_services"},{"description":"Lists available impact levels for a status page.","name":"list_status_page_impacts"},{"description":"Lists all updates for a specific status page post.","name":"list_status_page_post_updates","risk":{"category":"sends_externally","level":"medium","recommendation":"Restrict to specific channels; require confirmation before sending. Disable if the connector is used in untrusted contexts.","why":"Sends a message or post on the user's behalf to people or channels outside the conversation. Phishing, leaking secrets, or impersonation become possible if the tool is hijacked."}},{"description":"Lists available severity levels for a status page.","name":"list_status_page_severities"},{"description":"Lists available statuses for a status page.","name":"list_status_page_statuses"},{"description":"Lists all status pages with optional filtering.","name":"list_status_pages"},{"description":"Lists members of a team.","name":"list_team_members"},{"description":"Lists teams.","name":"list_teams"},{"description":"Lists users in the PagerDuty account.","name":"list_users"},{"description":"Updates status, urgency, assignment, or escalation level of incidents.","name":"manage_incidents","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"Removes a user from a team.","name":"remove_team_member","risk":{"category":"destructive","level":"high","recommendation":"Block by default. Only enable for read-only or sandbox accounts; require explicit human confirmation for any destructive action.","why":"Irreversibly removes data or resources. A prompt-injection or mistaken instruction could destroy production data with no recovery path."}},{"description":"Starts a workflow instance for an incident.","name":"start_incident_workflow"},{"description":"Updates an existing alert grouping setting.","name":"update_alert_grouping_setting","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"Updates the router configuration for an event orchestration.","name":"update_event_orchestration_router","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"Updates an existing schedule.","name":"update_schedule","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"Updates an existing service.","name":"update_service","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"Updates an existing team.","name":"update_team","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}}],"tools_count":64,"type":"web_connector","url":"https://claude.ai/directory/fc41b5e5-97bc-4c80-af18-e3a9442b655b","uuid":"2c563ef1-8ce6-5995-a37b-ef4fd72b2964","version":""},"query_key":"pagerduty pagerduty","schema_version":1,"status":"match"}
