Claude security directory

dbt

Published by dbt Labs

High risk

Discover, query, run, and manage your dbt projects directly from Claude. Browse models, sources, and lineage; query metrics from the semantic layer; and trigger jobs on the dbt platform. Make dbt a native part of your AI workflow that helps you understand your project, ship changes, and answer questions from your data faster, with full context and less friction.

Security assessment

Plutonium assessed this web connector for permissions, capabilities, and security-relevant behavior.

  • Reads your private information: Tools can query warehouse data (e.g., dimensions/metrics/SQL execution) and pull detailed project metadata (models, sources, lineage, run artifacts), which may include sensitive business logic or PII depending on your dbt setup.
  • Can change or update your information: Build/run/compile/parse and job-triggering capabilities can materially change datasets and downstream outputs by executing dbt transformations, altering what tables/views are produced and how analytics behaves.
  • Can permanently delete data: Running dbt jobs or arbitrary SQL can execute destructive operations (e.g., drop/truncate, full-refresh behaviors, or incremental overwrite patterns) that may permanently remove or overwrite warehouse data.
  • Can run commands or queries on your behalf: The connector can execute SQL and initiate dbt runs/tests/builds, which effectively runs code against your warehouse and CI/CD job infrastructure with potentially broad impact.
  • Stores long-lived access tokens: To manage projects and trigger/inspect dbt platform jobs, the connector typically relies on stored credentials/API tokens that, if compromised, could allow ongoing access to your dbt environment.

Available capabilities

This add-on exposes 60 tools or capabilities.

  • execute_sql
  • text_to_sql
  • get_dimension_values
  • get_dimensions
  • get_entities
  • get_metrics_compiled_sql
  • list_metrics
  • list_saved_queries
  • query_metrics
  • get_all_macros
  • get_all_models
  • get_all_sources
  • get_exposure_details
  • get_exposures
  • get_lineage
  • get_macro_details
  • get_mart_models
  • get_model_children
  • get_model_details
  • get_model_health
  • get_model_parents
  • get_model_performance
  • get_related_models
  • get_seed_details

The interactive security report will load automatically.