Claude security directory

Rapid7 Bulk Export

Published by Rapid7

High risk

Connects to the Rapid7 InsightVM Bulk Export API to fetch vulnerability and asset data, loads it into a local DuckDB database, and exposes SQL query tools for AI-powered security analysis. Vulnerability and asset inventories are highly sensitive - exposing them to the model means the AI sees your unpatched CVEs, exposed services, and scan history. The query_rapid7 tool runs arbitrary SQL against the local DuckDB, which is an in-process execution primitive against that database.

Security assessment

Plutonium assessed this desktop extension for permissions, capabilities, and security-relevant behavior.

  • Reads your private information: This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.
  • Can change or update your information: This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.

Available capabilities

This add-on exposes 8 tools or capabilities.

  • start_rapid7_export
  • check_rapid7_export_status
  • download_rapid7_export
  • load_rapid7_parquet
  • query_rapid7
  • get_rapid7_schema
  • get_rapid7_stats
  • list_rapid7_exports

The interactive security report will load automatically.