{"generated_at":"2026-08-08T12:20:51+00:00","item":{"added_at":"2026-03-04","analysis_method":"capability_triage","category":"Web Connector","description":"Create, query, and manage your structured content in Sanity directly from Claude. Run content audits, update documents, coordinate releases, and find anythin...","did":"io-sanity-www-mcp","homepage_url":"","icon":"https://icons.duckduckgo.com/ip3/www.sanity.io.ico","id":"io.sanity.www/mcp","installs":0,"last_scanned":"","license":"","long_description":"Create, query, and manage your structured content in Sanity directly from Claude. Run content audits, update documents, coordinate releases, and find anything across your projects. Or set up entirely new projects - schemas, content, and configuration - just by chatting with Claude.","name":"Sanity","plutonium_url":"https://plutonium.pluto.security/detail.html?planet=claudesec&did=io-sanity-www-mcp&utm_source=plutonium_analysis_skill&utm_medium=claude_skill&utm_campaign=connector_risk_assessment","publisher":"Sanity","publisher_url":"https://www.sanity.io","repository_url":"","risk":"medium","risk_severity":"medium","security_risks":[{"description":"This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.","evidence":"Connector has 31 tools; permissions on claude.ai/directory: \"Read and write\". Data flows out of the connected service into the model.","remediation":{"block_tool_categories":[],"steps":["Connect using an account that only has access to the information you actually want Claude to read - not your main admin login.","When you grant access, pick the smallest set of folders, mailboxes, or channels possible.","Check the connector's activity log every so often to make sure nothing unexpected is being read."]},"risk_type":"reads_private_data","severity":"medium","title":"Reads your private information"},{"description":"This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.","evidence":"11 state change tools on this connector - e.g. add_cors_origin, create_dataset, create_documents_from_json, create_documents_from_markdown and 7 more.","remediation":{"block_tool_categories":["state_change"],"steps":["Try the connector on a test account first to see what it changes before letting it touch your real records.","Where the connected service supports it, give Claude read-only access and only allow writes for the specific things you need updated.","In the tools list below, turn off any tool you don't actively need - the ones tagged Block are the most important to disable."]},"risk_type":"modifies_data","severity":"medium","title":"Can change or update your information"},{"description":"This connector can post messages, emails, or chat replies on your behalf. Recipients will believe the message came from you, which makes phishing or social-engineering risks higher.","evidence":"1 sends externally tool on this connector - e.g. publish_documents.","remediation":{"block_tool_categories":["sends_externally"],"steps":["In the tools list below, turn off any tool tagged Block if you don't need Claude to send messages or emails on your behalf.","If you do enable sending, restrict it to a private channel or distribution list - never customer-facing or company-wide.","Read the message before it goes out: don't let Claude send anything without you confirming first."]},"risk_type":"sends_messages_as_you","severity":"medium","title":"Can send messages as you"},{"description":"Anything you share with this connector flows through one or more third-party services. Those companies see, store, and may use the data according to their own policies.","evidence":"Server runs at mcp.sanity.io; queries and responses pass through the publisher's infrastructure.","remediation":{"block_tool_categories":[],"steps":["Treat anything you tell this connector as if you sent it directly to the third-party company - because you did.","Check how long that company keeps your data and how to delete it.","Avoid putting health info, customer names, or payment details into this connector unless you have a written agreement with that company."]},"risk_type":"forwards_data_to_third_party","severity":"low","title":"Sends your data to outside companies"}],"signature_status":"unknown","source_code_reviewed":false,"tags":["network_access","reads_private_data","code_deployment","email_messaging","database_access"],"tools":[{"description":"Add CORS origin(s) to allow client-side requests to a Sanity project.","name":"add_cors_origin","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"Create a new dataset with a specified name and access settings.","name":"create_dataset","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"Create one or more draft documents by directly providing JSON content, optionally targeting a release.","name":"create_documents_from_json","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"Create one or more draft documents from Markdown content, optionally targeting a release.","name":"create_documents_from_markdown","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"Create a new Sanity project and initialize it with a dataset and API tokens.","name":"create_project","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"Create a versioned document for a specific release, separate from drafts and published documents.","name":"create_version","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"Deploy schema types directly to the cloud.","name":"deploy_schema","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"Discard one or more draft documents while keeping published documents intact.","name":"discard_drafts"},{"description":"Fetch a single document by its exact ID for direct lookup of full content.","name":"get_document"},{"description":"Retrieve all studio applications linked to a specific Sanity project.","name":"get_project_studios"},{"description":"Load specific best-practice development rules for Sanity.","name":"get_sanity_rules"},{"description":"Get the full schema of the current Sanity workspace.","name":"get_schema"},{"description":"List all datasets in your Sanity project.","name":"list_datasets"},{"description":"List all available embeddings indices for a dataset.","name":"list_embeddings_indices"},{"description":"List all organizations the authenticated user has access to in Sanity.","name":"list_organizations"},{"description":"List all Sanity projects associated with your account.","name":"list_projects"},{"description":"List available best-practice development rules for Sanity.","name":"list_sanity_rules"},{"description":"Get a list of all available workspace schema names.","name":"list_workspace_schemas"},{"description":"Retrieve guides for migrating schemas and content from other CMS platforms to Sanity.","name":"migration_guide"},{"description":"Apply precise JSON-based modifications to document fields, creating or updating drafts as needed.","name":"patch_document_from_json","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"Patch a specific field in a document using Markdown content.","name":"patch_document_from_markdown","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"Publish one or more draft documents to make them live.","name":"publish_documents","risk":{"category":"sends_externally","level":"medium","recommendation":"Restrict to specific channels; require confirmation before sending. Disable if the connector is used in untrusted contexts.","why":"Sends a message or post on the user's behalf to people or channels outside the conversation. Phishing, leaking secrets, or impersonation become possible if the tool is hijacked."}},{"description":"Query documents from Sanity using the GROQ query language.","name":"query_documents"},{"description":"Fetch a specific Sanity documentation article.","name":"read_docs"},{"description":"Search Sanity documentation.","name":"search_docs"},{"description":"Perform a semantic search on an embeddings index.","name":"semantic_search"},{"description":"Unpublish one or more published documents, moving them back to drafts.","name":"unpublish_documents"},{"description":"Modify a dataset's name or access control settings.","name":"update_dataset","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"Discard one or more document versions from a release.","name":"version_discard"},{"description":"Replace the contents of a document version with contents from another document.","name":"version_replace_document","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"Mark a document to be unpublished when its release is executed.","name":"version_unpublish_document"}],"tools_count":31,"type":"web_connector","url":"https://claude.ai/directory/118aa78d-5b78-4e2b-9191-7a6af7cf822e","uuid":"14b66fe4-c9c0-50c8-bd8e-5c69a10837e1","version":""},"query_key":"sanity","schema_version":1,"status":"match"}
