{"generated_at":"2026-08-17T10:36:11+00:00","item":{"added_at":"2026-07-05","analysis_method":"capability_triage","category":"Web Connector","description":"Replit's MCP server lets users create, update, and manage full-stack web and mobile applications directly from Claude using natural language. Powered by Replit Agent, it transforms prompts into live, ","did":"ant-dir-replit","homepage_url":"https://replit.com","icon":"https://replit.com/favicon.ico","id":"ant.dir.replit","installs":15603,"last_scanned":"2026-07-05","license":"","long_description":"Replit's MCP server lets users create, update, and manage full-stack web and mobile applications directly from Claude using natural language. Powered by Replit Agent, it transforms prompts into live, deployed apps — complete with databases, authentication, and custom domains. Users can iterate on their apps conversationally, ask the Agent questions about their project, and access a live preview URL as the app builds. No coding experience required. The server supports OAuth 2.0 authentication and Streamable HTTP transport, integrating seamlessly with Replit's cloud development platform.","name":"Replit","plutonium_url":"https://plutonium.pluto.security/detail.html?planet=claudesec&did=ant-dir-replit&utm_source=plutonium_analysis_skill&utm_medium=claude_skill&utm_campaign=connector_risk_assessment","publisher":"Replit","publisher_url":"https://replit.com","repository_url":"","risk":"high","risk_severity":"high","security_risks":[{"description":"The connector can access application/project details and potentially view code, configuration, logs, or other sensitive workspace content when resolving apps or answering questions.","risk_type":"reads_private_data","severity":"medium","title":"Reads your private information"},{"description":"It can create and update apps from natural-language prompts, which may alter source code, configurations, dependencies, or project settings in your Replit workspace.","risk_type":"modifies_data","severity":"medium","title":"Can change or update your information"},{"description":"App creation/update workflows in a cloud dev platform typically involve executing build/run steps, which could execute arbitrary code paths and affect runtime behavior or access environment resources.","risk_type":"runs_code","severity":"high","title":"Can run commands or queries on your behalf"},{"description":"Uses OAuth 2.0, implying the connector may retain access/refresh tokens to maintain ongoing access to your Replit account and projects.","risk_type":"requires_persistent_credentials","severity":"medium","title":"Stores long-lived access tokens"},{"description":"Data processed via this connector is shared with Replit’s platform/services as part of app management and deployment operations.","risk_type":"forwards_data_to_third_party","severity":"low","title":"Sends your data to outside companies"}],"signature_status":"unknown","source_code_reviewed":false,"tags":["forwards_data_to_third_party","modifies_data","reads_private_data","requires_persistent_credentials","runs_code"],"tools":[{"description":"Creates a new Replit application from a natural-language prompt and provisions associated resources.","name":"create_app_from_prompt","risk":{"category":"code_execution","level":"high","why":"Creating an app usually triggers dependency installs/builds and may execute generated code in the environment, impacting security and resources."}},{"description":"Finds and returns an application/workspace based on its name.","name":"resolve_app_by_name"},{"description":"Modifies an existing Replit application using a natural-language prompt to change code or configuration.","name":"update_app_using_prompt","risk":{"category":"code_execution","level":"high","why":"Updating an app can change executable code and commonly triggers rebuild/restart steps that execute code paths in the environment."}},{"description":"Answers questions about the current project/app by inspecting its context and state.","name":"ask_question"},{"description":"Imports a design/spec into the project by fetching content from a provided URL.","name":"import-claude-design-from-url","risk":{"category":"sends_externally","level":"medium","why":"Fetching a remote URL and importing its contents can transmit metadata and may introduce untrusted external content into the project."}}],"tools_count":5,"type":"web_connector","url":"https://claude.ai/directory/b952bcd7-554a-460e-9c8a-a81074f9d430","uuid":"b952bcd7-554a-460e-9c8a-a81074f9d430","version":""},"query_key":"replit","schema_version":1,"status":"match"}
