Claude security directory

OneSignal

Published by OneSignal

High risk

The OneSignal MCP server gives AI agents direct access to OneSignal’s customer engagement platform. Agents can explore users, segments, messages, templates, and analytics; answer product and campaign questions; troubleshoot delivery and engagement issues; generate insights; and help create personalized omnichannel messaging across push, email, SMS, RCS, in-app messaging, and Live Activities.

Security assessment

Plutonium assessed this web connector for permissions, capabilities, and security-relevant behavior.

  • Can send messages as you: This connector can post messages, emails, or chat replies on your behalf. Recipients will believe the message came from you, which makes phishing or social-engineering risks higher.
  • Can change or update your information: This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.
  • Reads your private information: This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.
  • Sends your data to outside companies: Anything you share with this connector flows through one or more third-party services. Those companies see, store, and may use the data according to their own policies.

Available capabilities

This add-on exposes 29 tools or capabilities.

  • create_alias_by_subscription
  • create_or_update_alias
  • create_segment
  • create_subscription
  • create_template
  • create_user
  • export_audience_activity_csv
  • export_subscriptions_csv
  • get_segment
  • get_template
  • get_user_identity
  • get_user_identity_by_subscription
  • list_messages
  • list_segments
  • list_templates
  • onesignal_config
  • onesignal_health
  • onesignal_reference_overview
  • send_message
  • transfer_subscription
  • unsubscribe_email
  • update_segment
  • update_subscription
  • update_subscription_by_token

The interactive security report will load automatically.