{"generated_at":"2026-08-08T12:20:51+00:00","item":{"added_at":"2026-03-31T21:01:20.560000+00:00","analysis_method":"capability_triage","category":"Desktop Extension","description":"Pathmode MCP Server connects Claude Code, Cursor, and other AI agents to your product team's Intent Layer. AI agents get structured specifications (objective...","did":"ant-dir-gh-pathmode-pathmode","homepage_url":"","icon":"https://claude.ai/api/dxt/extensions/ant.dir.gh.pathmode.pathmode/versions/1.4.4/icon.png","id":"ant.dir.gh.pathmode.pathmode","installs":288,"last_scanned":"","license":"MIT","long_description":"Pathmode MCP Server connects Claude Code, Cursor, and other AI agents to your product team's Intent Layer. AI agents get structured specifications (objectives, outcomes, constraints, edge cases), dependency graph analysis (critical path, bottlenecks, cycles), and workspace strategy context - so they build the right thing, not just any thing.","name":"Pathmode","plutonium_url":"https://plutonium.pluto.security/detail.html?planet=claudesec&did=ant-dir-gh-pathmode-pathmode&utm_source=plutonium_analysis_skill&utm_medium=claude_skill&utm_campaign=connector_risk_assessment","publisher":"Pathmode","publisher_url":"https://pathmode.io","repository_url":"https://github.com/pathmodeio/mcp-server","risk":"medium","risk_severity":"medium","security_risks":[{"description":"This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.","evidence":"Connector has 20 tools; permissions on claude.ai/directory: \"unknown\". Data flows out of the connected service into the model.","remediation":{"block_tool_categories":[],"steps":["Connect using an account that only has access to the information you actually want Claude to read - not your main admin login.","When you grant access, pick the smallest set of folders, mailboxes, or channels possible.","Check the connector's activity log every so often to make sure nothing unexpected is being read."]},"risk_type":"reads_private_data","severity":"medium","title":"Reads your private information"},{"description":"This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.","evidence":"5 state change tools on this connector - e.g. update_intent_status, create_intent, update_intent, create_evidence and 1 more.","remediation":{"block_tool_categories":["state_change"],"steps":["Try the connector on a test account first to see what it changes before letting it touch your real records.","Where the connected service supports it, give Claude read-only access and only allow writes for the specific things you need updated.","In the tools list below, turn off any tool you don't actively need - the ones tagged Block are the most important to disable."]},"risk_type":"modifies_data","severity":"medium","title":"Can change or update your information"}],"signature_status":"unsigned","source_code_reviewed":true,"tags":["reads_private_data","database_access"],"tools":[{"description":"","name":"get_current_intent"},{"description":"","name":"list_intents"},{"description":"","name":"get_intent"},{"description":"","name":"get_intent_relations"},{"description":"","name":"search_intents"},{"description":"","name":"analyze_intent_graph"},{"description":"","name":"export_context","risk":{"category":"data_exfiltration","level":"medium","recommendation":"Restrict by row-count or scope at the API layer; alert on unusually large pulls.","why":"Pulls bulk data out of the source system. A prompt-injection attack can use this to siphon entire customer or revenue datasets in one call."}},{"description":"","name":"get_agent_prompt"},{"description":"","name":"get_workspace"},{"description":"","name":"get_constitution"},{"description":"","name":"update_intent_status","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"","name":"log_implementation_note"},{"description":"","name":"create_intent","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"","name":"update_intent","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"","name":"query_evidence"},{"description":"","name":"create_evidence","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"","name":"link_evidence"},{"description":"","name":"verify_implementation"},{"description":"","name":"intent_save","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"","name":"intent_export","risk":{"category":"data_exfiltration","level":"medium","recommendation":"Restrict by row-count or scope at the API layer; alert on unusually large pulls.","why":"Pulls bulk data out of the source system. A prompt-injection attack can use this to siphon entire customer or revenue datasets in one call."}}],"tools_count":20,"type":"desktop_extension","url":"","uuid":"c4de0daf-554f-5bc9-8e5b-1296bee90727","version":"1.4.4"},"query_key":"pathmode","schema_version":1,"status":"match"}
