{"generated_at":"2026-08-17T10:36:11+00:00","item":{"added_at":"2026-04-16","analysis_method":"capability_triage","category":"Web Connector","description":"Windows-MCP is an open-source project that enables seamless integration between AI agents and the Windows operating system. Acting as an MCP server, it bridg...","did":"windows-mcp","homepage_url":"","icon":"https://claude.ai/api/dxt/extensions/ant.dir.cursortouch.windows-mcp/versions/0.7.1/icon.png","id":"windows-mcp","installs":0,"last_scanned":"","license":"","long_description":"Windows-MCP is an open-source project that enables seamless integration between AI agents and the Windows operating system. Acting as an MCP server, it bridges the gap between large language models (LLMs) and the Windows OS, allowing agents to perform tasks such as file navigation, application control, UI interaction, QA testing, and more.\n\nKEY FEATURES\n- Seamless Windows Integration: Interacts natively with Windows UI elements, opens applications, controls win...","name":"Windows-MCP","plutonium_url":"https://plutonium.pluto.security/detail.html?planet=claudesec&did=windows-mcp&utm_source=plutonium_analysis_skill&utm_medium=claude_skill&utm_campaign=connector_risk_assessment","publisher":"","publisher_url":"","repository_url":"","risk":"high","risk_severity":"high","security_risks":[{"description":"This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.","evidence":"Connector has 18 tools; permissions on claude.ai/directory: \"unknown\". Data flows out of the connected service into the model.","remediation":{"block_tool_categories":[],"steps":["Connect using an account that only has access to the information you actually want Claude to read - not your main admin login.","When you grant access, pick the smallest set of folders, mailboxes, or channels possible.","Check the connector's activity log every so often to make sure nothing unexpected is being read."]},"risk_type":"reads_private_data","severity":"medium","title":"Reads your private information"},{"description":"This connector can execute scripts, shell commands, or arbitrary database queries. In a worst case, an attacker could install software, read files, or pull or change any data its login can reach.","evidence":"1 code execution tool on this connector - e.g. PowerShell.","remediation":{"block_tool_categories":["code_execution"],"steps":["In the tools list below, turn off any tool tagged Block before connecting this to real data or production systems.","If you need code execution, run it on a separate test machine that has no access to your work files, customer data, or saved passwords.","Limit which websites and services that test machine can talk to."]},"risk_type":"runs_code","severity":"high","title":"Can run commands or queries on your behalf"},{"description":"This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.","evidence":"2 state change tools on this connector - e.g. Move, MultiEdit.","remediation":{"block_tool_categories":["state_change"],"steps":["Try the connector on a test account first to see what it changes before letting it touch your real records.","Where the connected service supports it, give Claude read-only access and only allow writes for the specific things you need updated.","In the tools list below, turn off any tool you don't actively need - the ones tagged Block are the most important to disable."]},"risk_type":"modifies_data","severity":"medium","title":"Can change or update your information"}],"signature_status":"unknown","source_code_reviewed":false,"tags":["network_access","reads_private_data","shell_access","filesystem_access","browser_control","database_access"],"tools":[{"description":"Launches applications from the start menu, resizes or moves windows, and switches between apps.","name":"App"},{"description":"Executes PowerShell commands on the Windows system.","name":"PowerShell","risk":{"category":"code_execution","level":"high","recommendation":"Block in production. If needed, scope tightly to a sandboxed account and disallow shell/SQL passthrough.","why":"Runs arbitrary code, queries, or shell commands. Effectively grants the model the same privileges as the configured account on the target system."}},{"description":"","name":"FileSystem"},{"description":"Captures a fast screenshot of the desktop including cursor position and active/open windows.","name":"Screenshot"},{"description":"Captures full desktop state including interactive element IDs, scrollable regions, and optional DOM browser extraction.","name":"Snapshot"},{"description":"Clicks on the screen at specified coordinates.","name":"Click"},{"description":"Types text into an element, with an option to clear existing text first.","name":"Type"},{"description":"Scrolls vertically or horizontally on a window or specific screen regions.","name":"Scroll"},{"description":"Moves the mouse pointer or drags it to specified coordinates.","name":"Move","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"Presses keyboard shortcuts such as Ctrl+C or Alt+Tab.","name":"Shortcut"},{"description":"Pauses execution for a defined duration.","name":"Wait"},{"description":"Scrapes an entire webpage to extract information.","name":"Scrape"},{"description":"Selects multiple items such as files, folders, or checkboxes with optional Ctrl key support.","name":"MultiSelect"},{"description":"Enters text into multiple input fields at specified coordinates using bulk label-to-coordinate resolution.","name":"MultiEdit","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"Reads or sets the Windows clipboard content.","name":"Clipboard"},{"description":"Lists running processes or terminates them by PID or name.","name":"Process"},{"description":"Sends a Windows toast notification with a specified title and message.","name":"Notification"},{"description":"Reads, writes, deletes, or lists Windows Registry values and keys.","name":"Registry"}],"tools_count":18,"type":"web_connector","url":"https://claude.ai/directory","uuid":"3a1ebd29-a897-50a9-854e-66bb16b8848b","version":"0.7.1"},"query_key":"windows mcp","schema_version":1,"status":"match"}
