{"generated_at":"2026-08-17T10:36:11+00:00","item":{"added_at":"2025-11-12","analysis_method":"capability_triage","category":"Web Connector","description":"Enables secure, read-only access to Ramp data for customer-defined logic. Supports loading and querying transactions, reimbursements, bills, purchase orders,...","did":"com-ramp-ramp-mcp-remote-ramp","homepage_url":"","icon":"https://ramp.com/favicon.ico","id":"com.ramp.ramp-mcp-remote/ramp","installs":0,"last_scanned":"","license":"","long_description":"Enables secure, read-only access to Ramp data for customer-defined logic. Supports loading and querying transactions, reimbursements, bills, purchase orders, cards, vendors, and more, enabling dynamic data fetching and analysis via Claude.","name":"Ramp","plutonium_url":"https://plutonium.pluto.security/detail.html?planet=claudesec&did=com-ramp-ramp-mcp-remote-ramp&utm_source=plutonium_analysis_skill&utm_medium=claude_skill&utm_campaign=connector_risk_assessment","publisher":"Ramp","publisher_url":"https://ramp.com/","repository_url":"","risk":"high","risk_severity":"high","security_risks":[{"description":"This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.","evidence":"Connector has 17 tools; permissions on claude.ai/directory: \"Read and write\". Data flows out of the connected service into the model.","remediation":{"block_tool_categories":[],"steps":["Connect using an account that only has access to the information you actually want Claude to read - not your main admin login.","When you grant access, pick the smallest set of folders, mailboxes, or channels possible.","Check the connector's activity log every so often to make sure nothing unexpected is being read."]},"risk_type":"reads_private_data","severity":"medium","title":"Reads your private information"},{"description":"This connector can erase records, files, or accounts. Once deleted the data may be unrecoverable - even an accidental request can cause permanent loss.","evidence":"1 destructive tool on this connector - e.g. clear_table.","remediation":{"block_tool_categories":["destructive"],"steps":["In the tools list below, turn off any tool tagged Block - most workflows don't need Claude to delete anything.","If you really do need deletion, use a login that doesn't have delete permission and have a person handle removals manually.","Make sure the connected service has a trash / recycle bin enabled so accidental deletes can be recovered."]},"risk_type":"deletes_data","severity":"high","title":"Can permanently delete data"},{"description":"This connector can complete purchases, bookings, or payments. A misused or hijacked prompt could result in real financial charges before you confirm.","evidence":"1 financial tool on this connector - e.g. load_purchase_orders.","remediation":{"block_tool_categories":["financial"],"steps":["In the tools list below, turn off any tool tagged Block by default; only enable them when you actually want Claude to make a purchase.","Set a spending limit on the linked credit card, billing account, or virtual card so a mistake can't cost you much.","Always confirm in the chat before Claude completes a payment or books anything."]},"risk_type":"spends_money","severity":"high","title":"Can spend money on your behalf"},{"description":"Anything you share with this connector flows through one or more third-party services. Those companies see, store, and may use the data according to their own policies.","evidence":"Server runs at ramp-mcp-remote.ramp.com/mcp; queries and responses pass through the publisher's infrastructure.","remediation":{"block_tool_categories":[],"steps":["Treat anything you tell this connector as if you sent it directly to the third-party company - because you did.","Check how long that company keeps your data and how to delete it.","Avoid putting health info, customer names, or payment details into this connector unless you have a written agreement with that company."]},"risk_type":"forwards_data_to_third_party","severity":"low","title":"Sends your data to outside companies"}],"signature_status":"unknown","source_code_reviewed":false,"tags":["network_access","reads_private_data","shell_access","database_access","deletes_data","financial_ops"],"tools":[{"description":"Run SQL queries on loaded data.","name":"execute_query"},{"description":"Clear specific tables from memory.","name":"clear_table","risk":{"category":"destructive","level":"high","recommendation":"Block by default. Only enable for read-only or sandbox accounts; require explicit human confirmation for any destructive action.","why":"Irreversibly removes data or resources. A prompt-injection or mistaken instruction could destroy production data with no recovery path."}},{"description":"Load transactions, reimbursements, and bills (recommended).","name":"load_spend_export","risk":{"category":"data_exfiltration","level":"medium","recommendation":"Restrict by row-count or scope at the API layer; alert on unusually large pulls.","why":"Pulls bulk data out of the source system. A prompt-injection attack can use this to siphon entire customer or revenue datasets in one call."}},{"description":"","name":"load_spend_exports"},{"description":"Load purchase order data.","name":"load_purchase_orders","risk":{"category":"financial","level":"high","recommendation":"Block by default. Require human-in-the-loop confirmation for every transaction; do not allow autonomous execution.","why":"Initiates a financial transaction or paid action. A confused-deputy or prompt-injection scenario can spend money on the user's behalf."}},{"description":"Load card information.","name":"load_cards"},{"description":"Load spending limit data.","name":"load_limits"},{"description":"Load entity information.","name":"load_entities"},{"description":"Load department data.","name":"load_departments"},{"description":"Load user/employee data.","name":"load_users"},{"description":"Load memo data.","name":"load_memos"},{"description":"Load office location data.","name":"load_locations"},{"description":"Load spend program data.","name":"load_spend_programs"},{"description":"Load vendor information.","name":"load_vendors"},{"description":"Get all available Ramp spending categories.","name":"get_ramp_categories"},{"description":"Submit feedback about Developer MCP, Ramp's API docs, or confusing tool results.","name":"submit_feedback"},{"description":"","name":"get_current_user"}],"tools_count":17,"type":"web_connector","url":"https://claude.ai/directory/61bac03c-3f98-4b3c-affb-1b99533fa82c","uuid":"e121fd74-8f13-51e9-bcf3-a5851f40efd5","version":""},"query_key":"ramp","schema_version":1,"status":"match"}
