Claude security directory

monday.com

Published by monday.com

High risk

The monday MCP server exposes core monday.com capabilities to agents. It enables actions like searching boards, creating and updating items and columns, assigning owners, setting timelines, and posting updates - supporting a wide range of work management use cases across teams and departments.

Security assessment

Plutonium assessed this interactive connector for permissions, capabilities, and security-relevant behavior.

  • Reads your private information: This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.
  • Can permanently delete data: This connector can erase records, files, or accounts. Once deleted the data may be unrecoverable - even an accidental request can cause permanent loss.
  • Can change or update your information: This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.
  • Sends your data to outside companies: Anything you share with this connector flows through one or more third-party services. Those companies see, store, and may use the data according to their own policies.

Available capabilities

This add-on exposes 20 tools or capabilities.

  • delete_item
  • get_board_items_by_name
  • create_item
  • create_update
  • get_board_schema
  • get_users_by_name
  • change_item_column_values
  • move_item_to_group
  • create_board
  • create_column
  • delete_column
  • all_monday_api
  • get_graphql_schema
  • get_type_details
  • create_custom_activity
  • create_timeline_item
  • fetch_custom_activity
  • create_workflow_instructions
  • read_docs
  • workspace_info

The interactive security report will load automatically.