Claude security directory
Quinbook
Medium risk
MCP server exposing the quinbook API. Read tools for slots, orders, coupons and contacts; write tools for cart, order lifecycle and contacts that execute immediately (the bundled skills require confirming with the user first). OAuth login with your own quinbook credentials; multi-tenant via me_switch_company.
Security assessment
Plutonium assessed this web connector for permissions, capabilities, and security-relevant behavior.
- Reads your private information: The connector can read potentially sensitive business data such as orders, contacts, coupons, and scheduling/slot information across your Quinbook tenant(s).
- Can change or update your information: It includes write operations for carts, order lifecycle actions, and contacts that can immediately change records and workflows in Quinbook.
- Stores long-lived access tokens: OAuth authentication implies storing an access token for ongoing access to your Quinbook account, potentially spanning multiple companies via tenant switching.
The interactive security report will load automatically.