Claude security directory
Agility CMS
Published by Agility CMS
High risk
Agility CMS is a headless content management system built for teams that want marketers in control and developers unblocked. This MCP server gives AI assistants authenticated access to your Agility instances so you can model content, author pages, publish updates, and manage media through natural language instead of clicking through admin screens. 27 tools cover the full authoring and publishing workflow. Discover instances, locales, containers, and sitemaps. Inspect or change content models, component models, and page templates. Retrieve, create, update, publish, or delete content items across multiple locales. Compose pages from zones and modules. Upload, browse, and remove media. Move items and pages through approval. Works across multiple Agility instances under one account, so agencies and enterprises with several brands can switch contexts in a single conversation. Authentication is OAuth 2.0 against your existing Agility account, and the MCP server inherits the permissions you already have. Read-only users stay read-only. The server can't escalate access beyond what your account already grants. Destructive actions are gated. Publish and unpublish ask for explicit confirmation. Deletes require typing DELETE. On clients that support MCP elicitation, those prompts render in your own UI so the AI assistant can't satisfy them on its own. Use it to scaffold content models from a spec, compose landing pages from a brief, audit cross-locale content, generate TypeScript types from your schema, migrate spreadsheets into product catalogs, or build a Next.js site with its content models in a single conversation.
Security assessment
Plutonium assessed this web connector for permissions, capabilities, and security-relevant behavior.
- Can permanently delete data: This connector can erase records, files, or accounts. Once deleted the data may be unrecoverable - even an accidental request can cause permanent loss.
- Can change or update your information: This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.
- Reads your private information: This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.
- Sends your data to outside companies: Anything you share with this connector flows through one or more third-party services. Those companies see, store, and may use the data according to their own policies.
Available capabilities
This add-on exposes 27 tools or capabilities.
- delete_content_item
- delete_media
- delete_page
- get_available_instances
- get_component_model_details
- get_component_models
- get_containers
- get_content_item
- get_content_items
- get_content_model_details
- get_content_models
- get_current_user
- get_locales
- get_page
- get_page_models
- get_sitemap
- get_sitemaps
- initialize_media_upload
- list_media
- manage_content_workflow
- manage_page_workflow
- reorder_page_modules
- save_component_model
- save_container
The interactive security report will load automatically.