Claude security directory
Replit
Published by Replit
High risk
Replit's MCP server lets users create, update, and manage full-stack web and mobile applications directly from Claude using natural language. Powered by Replit Agent, it transforms prompts into live, deployed apps — complete with databases, authentication, and custom domains. Users can iterate on their apps conversationally, ask the Agent questions about their project, and access a live preview URL as the app builds. No coding experience required. The server supports OAuth 2.0 authentication and Streamable HTTP transport, integrating seamlessly with Replit's cloud development platform.
Security assessment
Plutonium assessed this web connector for permissions, capabilities, and security-relevant behavior.
- Reads your private information: The connector can access application/project details and potentially view code, configuration, logs, or other sensitive workspace content when resolving apps or answering questions.
- Can change or update your information: It can create and update apps from natural-language prompts, which may alter source code, configurations, dependencies, or project settings in your Replit workspace.
- Can run commands or queries on your behalf: App creation/update workflows in a cloud dev platform typically involve executing build/run steps, which could execute arbitrary code paths and affect runtime behavior or access environment resources.
- Stores long-lived access tokens: Uses OAuth 2.0, implying the connector may retain access/refresh tokens to maintain ongoing access to your Replit account and projects.
- Sends your data to outside companies: Data processed via this connector is shared with Replit’s platform/services as part of app management and deployment operations.
Available capabilities
This add-on exposes 5 tools or capabilities.
- create_app_from_prompt
- resolve_app_by_name
- update_app_using_prompt
- ask_question
- import-claude-design-from-url
The interactive security report will load automatically.