Claude security directory

mittwald

Published by mittwald

High risk

Manage your mittwald hosting infrastructure through natural conversation — without leaving Claude. This connector gives Claude direct access to the mittwald Cloud Platform: - Projects & servers — create, inspect and update projects, check filesystem usage, manage memberships and invites - Apps — install and manage PHP, Node.js, Python and static apps; track dependencies and apply upgrades - Containers & stacks — deploy stacks, start/stop/restart containers, stream logs, manage registries and volumes - Databases — administer MySQL and Redis instances and their users; get ready-to-run commands for dumps, imports, port forwarding and phpMyAdmin - Domains, DNS & certificates — inspect domains, edit DNS zones, configure virtual hosts, request TLS certificates - Mail — manage mail addresses and delivery boxes - Cronjobs — schedule, trigger and inspect jobs and their execution logs - Access — SSH and SFTP users, SSH keys, API tokens, sessions, organisation members - Backups — create backups and schedules, list them, retrieve download URLs Authentication runs through OAuth 2.1 with PKCE against your mittwald account, so Claude only acts with the permissions you grant — no API tokens to copy around. For safety, the connector never opens shells, tunnels or file transfers itself. SSH access, database dumps and backup downloads come back as a command or URL for you to run locally, keeping credentials and data on your machine.

Security assessment

Plutonium assessed this web connector for permissions, capabilities, and security-relevant behavior.

  • Can permanently delete data: This connector can erase records, files, or accounts. Once deleted the data may be unrecoverable - even an accidental request can cause permanent loss.
  • Can run commands or queries on your behalf: This connector can execute scripts, shell commands, or arbitrary database queries. In a worst case, an attacker could install software, read files, or pull or change any data its login can reach.
  • Can change or update your information: This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.
  • Reads your private information: This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.
  • Sends your data to outside companies: Anything you share with this connector flows through one or more third-party services. Those companies see, store, and may use the data according to their own policies.

Available capabilities

This add-on exposes 116 tools or capabilities.

  • mittwald_app_copy
  • mittwald_app_get
  • mittwald_app_list
  • mittwald_app_list_upgrade_candidates
  • mittwald_app_ssh
  • mittwald_app_uninstall
  • mittwald_app_update
  • mittwald_app_upgrade
  • mittwald_app_versions
  • mittwald_backup_create
  • mittwald_backup_delete
  • mittwald_backup_download
  • mittwald_backup_get
  • mittwald_backup_list
  • mittwald_backup_schedule_create
  • mittwald_backup_schedule_delete
  • mittwald_backup_schedule_list
  • mittwald_backup_schedule_update
  • mittwald_certificate_list
  • mittwald_certificate_request
  • mittwald_container_delete
  • mittwald_container_list
  • mittwald_container_logs
  • mittwald_container_restart

The interactive security report will load automatically.