Claude security directory
Ultipa
High risk
Model Context Protocol server for Ultipa Cloud and any self-managed Ultipa GQLDB instance. Provision and operate instances, run GQL queries and graph algorithms, manage backups and firewall rules, and view metrics and billing — all through natural language.
Security assessment
Plutonium assessed this web connector for permissions, capabilities, and security-relevant behavior.
- Reads your private information: The connector can access account details, instance logs/metrics, backups, billing/transactions, and database schema/data, which may contain sensitive operational or personal information.
- Can change or update your information: The connector can create/rename/upgrade/restart instances, modify firewall rules and backup schedules, and write/import database data and procedures.
- Can permanently delete data: The connector can delete instances, graphs, and backups, which may cause irreversible loss of infrastructure and stored data if used incorrectly or maliciously.
- Can run commands or queries on your behalf: The connector can execute GQL queries and graph algorithms and can write procedures, enabling powerful actions that could exfiltrate data, alter datasets, or impact availability.
- Can spend money on your behalf: By provisioning and operating instances (and potentially triggering paid usage), the connector can increase costs; it also exposes billing, balance, and payment configuration surfaces.
- Stores long-lived access tokens: Managing cloud instances and database operations typically requires stored credentials; compromise of these tokens could grant broad access to infrastructure and data.
Available capabilities
This add-on exposes 56 tools or capabilities.
- get_account
- list_instances
- list_deleted_instances
- get_instance
- get_instance_credentials
- list_regions
- list_instance_sizes
- get_enterprise_status
- get_operations_lock
- get_trial_status
- get_latest_version
- create_instance
- rename_instance
- pause_instance
- resume_instance
- restart_instance
- upgrade_version
- delete_instance
- reset_admin_password
- set_log_level
- wait_for_instance_status
- get_live_metrics
- get_metrics_history
- get_instance_logs
The interactive security report will load automatically.