{"generated_at":"2026-08-17T10:36:11+00:00","item":{"added_at":"2026-02-09","analysis_method":"capability_triage","category":"Web Connector","description":"Yardi Virtuoso provides secure, real-time access to Yardi data and tools through Claude. It enables investment, property and asset management professionals t...","did":"com-yardi-virtuoso","homepage_url":"","icon":"https://yardi.com/apple-touch-icon.png","id":"com.yardi/virtuoso","installs":0,"last_scanned":"","license":"","long_description":"Yardi Virtuoso provides secure, real-time access to Yardi data and tools through Claude. It enables investment, property and asset management professionals to query financial models, predictive maintenance insights, market analysis, and portfolio data using natural language. Users can ask complex operational questions, explore strategic scenarios, and perform analysis without manual data extraction, all grounded in accurate, enterprise-grade Yardi data.","name":"Yardi Virtuoso","plutonium_url":"https://plutonium.pluto.security/detail.html?planet=claudesec&did=com-yardi-virtuoso&utm_source=plutonium_analysis_skill&utm_medium=claude_skill&utm_campaign=connector_risk_assessment","publisher":"Yardi","publisher_url":"https://yardi.com","repository_url":"","risk":"high","risk_severity":"high","security_risks":[{"description":"This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.","evidence":"Connector has 5 tools; permissions on claude.ai/directory: \"Read and write\". Data flows out of the connected service into the model.","remediation":{"block_tool_categories":[],"steps":["Connect using an account that only has access to the information you actually want Claude to read - not your main admin login.","When you grant access, pick the smallest set of folders, mailboxes, or channels possible.","Check the connector's activity log every so often to make sure nothing unexpected is being read."]},"risk_type":"reads_private_data","severity":"medium","title":"Reads your private information"},{"description":"This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.","evidence":"1 state change tool on this connector - e.g. rfm_connectai_create_work_order.","remediation":{"block_tool_categories":["state_change"],"steps":["Try the connector on a test account first to see what it changes before letting it touch your real records.","Where the connected service supports it, give Claude read-only access and only allow writes for the specific things you need updated.","In the tools list below, turn off any tool you don't actively need - the ones tagged Block are the most important to disable."]},"risk_type":"modifies_data","severity":"medium","title":"Can change or update your information"},{"description":"This connector can complete purchases, bookings, or payments. A misused or hijacked prompt could result in real financial charges before you confirm.","evidence":"1 financial tool on this connector - e.g. rfm_workorder_mark_work_order_as_complete.","remediation":{"block_tool_categories":["financial"],"steps":["In the tools list below, turn off any tool tagged Block by default; only enable them when you actually want Claude to make a purchase.","Set a spending limit on the linked credit card, billing account, or virtual card so a mistake can't cost you much.","Always confirm in the chat before Claude completes a payment or books anything."]},"risk_type":"spends_money","severity":"high","title":"Can spend money on your behalf"},{"description":"Anything you share with this connector flows through one or more third-party services. Those companies see, store, and may use the data according to their own policies.","evidence":"Server runs at mcp.virtuoso.ai/mcp; queries and responses pass through the publisher's infrastructure.","remediation":{"block_tool_categories":[],"steps":["Treat anything you tell this connector as if you sent it directly to the third-party company - because you did.","Check how long that company keeps your data and how to delete it.","Avoid putting health info, customer names, or payment details into this connector unless you have a written agreement with that company."]},"risk_type":"forwards_data_to_third_party","severity":"low","title":"Sends your data to outside companies"}],"signature_status":"unknown","source_code_reviewed":false,"tags":["network_access","reads_private_data","financial_ops"],"tools":[{"description":"Creates new work orders in Yardi with details like descriptions, property, unit, priority, categories, attachments, and access notes.","name":"rfm_connectai_create_work_order","risk":{"category":"financial","level":"high","recommendation":"Block by default. Require human-in-the-loop confirmation for every transaction; do not allow autonomous execution.","why":"Initiates a financial transaction or paid action. A confused-deputy or prompt-injection scenario can spend money on the user's behalf."}},{"description":"Searches and filters work orders by dates, priority, status, category, employee, vendor, property, unit, tenant, and more, returning up to 5000 records.","name":"rfm_connectai_search_work_orders"},{"description":"Closes completed work orders by recording the completion date and adding final technician notes and descriptions.","name":"rfm_workorder_mark_work_order_as_complete","risk":{"category":"financial","level":"high","recommendation":"Block by default. Require human-in-the-loop confirmation for every transaction; do not allow autonomous execution.","why":"Initiates a financial transaction or paid action. A confused-deputy or prompt-injection scenario can spend money on the user's behalf."}},{"description":"Returns autocomplete suggestions for entity types such as properties, vendors, tenants, units, employees, and roles using free-text search with exact or partial matching.","name":"vn_mcpframework_get_autocomplete"},{"description":"Returns the list of available autocomplete entity types that can be queried using the autocomplete tool.","name":"vn_mcpframework_list_autocomplete_types"}],"tools_count":5,"type":"web_connector","url":"https://claude.ai/directory/01953ddd-4139-40c5-bbf9-47c1e2499623","uuid":"a90c7bb6-91c0-589c-b7ac-6ee84a056a1d","version":""},"query_key":"yardi virtuoso","schema_version":1,"status":"match"}
