Claude security directory

Denodo MCP Connector

High risk

This extension connects Claude Desktop to a running Denodo MCP Server, enabling AI-powered querying of Denodo Virtual DataPort databases. Supports three authentication modes: (1) Basic Auth with username and password; (2) OAuth bearer token — paste a static JWT, optionally with automatic refresh via a refresh token grant; (3) OAuth Authorization Code flow — a browser window opens for you to log in, and the connector handles token refresh silently from then on (uses PKCE for public clients). Requires a Denodo MCP Server (v9, build 20260317 or later) running and accessible.

Security assessment

Plutonium assessed this desktop extension for permissions, capabilities, and security-relevant behavior.

  • Can run commands or queries on your behalf: This connector can execute scripts, shell commands, or arbitrary database queries. In a worst case, an attacker could install software, read files, or pull or change any data its login can reach.
  • Reads your private information: This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.

Available capabilities

This add-on exposes 6 tools or capabilities.

  • get_database_schema
  • get_view_names
  • get_view_schema
  • run_vql_query
  • validate_vql_query
  • <database_name>_query_<tagged_view_name>

The interactive security report will load automatically.