Claude security directory
Order by Cash App
Published by Block, Inc.
High risk
Order by Cash App brings local food ordering into Claude. Discover nearby restaurants, compare menus, customize your order, and check out, all in the conversation. On clients that support it, an interactive ordering view opens right in chat.
Security assessment
Plutonium assessed this web connector for permissions, capabilities, and security-relevant behavior.
- Reads your private information: The connector can access sensitive ordering context such as nearby restaurant discovery (implying location) and menu/cart details that may reveal preferences or dietary information.
- Can change or update your information: The connector can create and modify an order cart, potentially adding items, quantities, modifiers, and other order details without additional safeguards.
- Can spend money on your behalf: Because it supports checkout/ordering flows, misuse could lead to unintended purchases or charges if the toolchain proceeds from cart creation to payment authorization.
- Sends your data to outside companies: Using the connector necessarily transmits order details and possibly location context to Cash App and participating merchants to fulfill restaurant discovery and ordering.
- Stores long-lived access tokens: Ordering typically requires an authenticated Cash App session; if long-lived tokens are stored, compromise could allow continued access to ordering capabilities.
Available capabilities
This add-on exposes 7 tools or capabilities.
- discover-nearby-restaurants
- get-multiple-menus
- get-restaurant-ordering-view
- get-single-menu-view
- get-single-menu
- create-cart
- app_create-cart
The interactive security report will load automatically.