Claude security directory

Macos

Published by CursorTouch

High risk

MacOS-MCP is a lightweight, open-source MCP server that bridges AI agents with the macOS operating system. It enables LLM agents to perform real-world tasks such as app launching, window management, UI interaction, browser automation, desktop state capture, and shell execution using native macOS accessibility and automation APIs. KEY FEATURES - Native macOS Integration: Interact with applications, windows, and UI elements through the macOS Accessibility API and Qu...

Security assessment

Plutonium assessed this desktop extension for permissions, capabilities, and security-relevant behavior.

  • Reads your private information: This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.
  • Can run commands or queries on your behalf: This connector can execute scripts, shell commands, or arbitrary database queries. In a worst case, an attacker could install software, read files, or pull or change any data its login can reach.
  • Can change or update your information: This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.

Available capabilities

This add-on exposes 10 tools or capabilities.

  • App
  • Shell
  • Snapshot
  • Click
  • Type
  • Scroll
  • Move
  • Shortcut
  • Wait
  • Scrape

The interactive security report will load automatically.