Claude security directory

Macaly Cloud

Published by Macaly

High risk

Macaly Cloud turns Macaly into the infrastructure behind Claude. Claude writes every line of code; Macaly supplies the git repository, the cloud sandbox, the database and platform capabilities, the build, a shareable live preview, and production hosting on macaly.com. What you can do: Create a new app, or continue one you already have. Every app lives in your Macaly workspace from the first file, so you can open it in the Macaly visual editor at any time and keep building there - or hand it back to Claude later. Read, write and delete source files. Each change is its own commit in the project’s git history, so nothing is silently lost. Run commands in the project’s isolated cloud sandbox: type checks, package installs, database setup and the scripts behind Macaly’s platform capabilities - Convex database, authentication, payments, media generation, search. Read build and dev-server logs when a check fails, so Claude can fix the error instead of guessing. Get a live preview URL to share, publish to production when you explicitly ask, and connect a custom domain. Apps are TanStack Start + Vite + Tailwind with Convex as the backend. Claude reads a project briefing and per-capability guides from the server before it writes code, so what it produces fits the platform. You connect in one click with OAuth (or a team-scoped API key). Claude can only reach the Macaly workspaces your account can reach - never your local machine, never another user’s projects. Publishing and domain changes are separate, explicit actions that are never taken on their own. Docs: https://www.macaly.com/docs/en/integrations/macaly-cloud

Security assessment

Plutonium assessed this web connector for permissions, capabilities, and security-relevant behavior.

  • Can permanently delete data: This connector can erase records, files, or accounts. Once deleted the data may be unrecoverable - even an accidental request can cause permanent loss.
  • Can run commands or queries on your behalf: This connector can execute scripts, shell commands, or arbitrary database queries. In a worst case, an attacker could install software, read files, or pull or change any data its login can reach.
  • Can change or update your information: This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.
  • Reads your private information: This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.
  • Sends your data to outside companies: Anything you share with this connector flows through one or more third-party services. Those companies see, store, and may use the data according to their own policies.

Available capabilities

This add-on exposes 16 tools or capabilities.

  • connect_domain
  • create_app
  • delete_file
  • duplicate_app
  • get_deployment
  • get_logs
  • get_project
  • list_files
  • list_projects
  • list_teams
  • preview_app
  • publish_app
  • read_file
  • run_project_command
  • skill_info
  • write_file

The interactive security report will load automatically.