Claude security directory
Padlet MCP
Published by Wallwisher, Inc.
High risk
Padlet is a visual board platform used by teachers, students, and teams to collect, organize, and share content on collaborative boards called padlets. The Padlet connector links the user's own Padlet account via OAuth so they can work with their padlets directly in conversation. With this connector, users can: - Create padlets and organize them with sections, layouts, wallpapers, and appearance settings. - Add, edit, arrange, pin, and sort posts, and draw connections between posts on Freeform boards. - Read, search, and summarize board content, including AI analysis of images, videos, audio, and document attachments. - Comment on posts and moderate discussion. - Manage sharing settings by modifying permissions, passwords, collaborators, and email invitations. - Schedule automations such as timed freezes, and freeze or unfreeze boards on demand. - Grade student submissions and sync grades to a connected LMS (e.g. Canvas or Schoology) via LTI. - For school and team library admins: manage membership and invitations, per-role permissions, SSO configuration (OAuth providers and SAML), approved email domains, content safety, and allowed attachment types. The connector does not yet fully support Padlet's Sandbox (whiteboard) format; it works with Padlet's other board formats. All actions run against the authenticated user's Padlet account and respect Padlet's permission model — the connector can only see and change what the signed-in user could see and change in Padlet itself. Deletions of posts and sections are soft-deletes that can be restored with a dedicated restore tool, and the small number of irreversible operations (deleting comments, automations, or custom fields, removing collaborators, invitations, or approved domains) are annotated as destructive so the assistant confirms with the user before proceeding.
Security assessment
Plutonium assessed this web connector for permissions, capabilities, and security-relevant behavior.
- Can permanently delete data: This connector can erase records, files, or accounts. Once deleted the data may be unrecoverable - even an accidental request can cause permanent loss.
- Can send messages as you: This connector can post messages, emails, or chat replies on your behalf. Recipients will believe the message came from you, which makes phishing or social-engineering risks higher.
- Can change or update your information: This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.
- Reads your private information: This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.
- Sends your data to outside companies: Anything you share with this connector flows through one or more third-party services. Those companies see, store, and may use the data according to their own policies.
Available capabilities
This add-on exposes 76 tools or capabilities.
- add_comment_to_post
- add_library_approved_domain
- analyze_post_attachments
- bulk_invite_library_members
- complete_library_onboarding_step
- create_automation
- create_library_saml_connection
- create_padlet
- create_padlet_arcade_activity
- create_post_connection
- create_posts
- delete_automations
- delete_comment
- delete_custom_fields
- delete_post_connection
- freeze_padlet
- get_comment_url
- get_current_user_info
- get_library_approved_domains
- get_library_attachment_type_settings
- get_library_content_safety
- get_library_info
- get_library_invite_links
- get_library_oauth_settings
The interactive security report will load automatically.