Claude security directory

Windows-MCP

High risk

Windows-MCP is an open-source project that enables seamless integration between AI agents and the Windows operating system. Acting as an MCP server, it bridges the gap between large language models (LLMs) and the Windows OS, allowing agents to perform tasks such as file navigation, application control, UI interaction, QA testing, and more. KEY FEATURES - Seamless Windows Integration: Interacts natively with Windows UI elements, opens applications, controls win...

Security assessment

Plutonium assessed this web connector for permissions, capabilities, and security-relevant behavior.

  • Reads your private information: This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.
  • Can run commands or queries on your behalf: This connector can execute scripts, shell commands, or arbitrary database queries. In a worst case, an attacker could install software, read files, or pull or change any data its login can reach.
  • Can change or update your information: This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.

Available capabilities

This add-on exposes 18 tools or capabilities.

  • App
  • PowerShell
  • FileSystem
  • Screenshot
  • Snapshot
  • Click
  • Type
  • Scroll
  • Move
  • Shortcut
  • Wait
  • Scrape
  • MultiSelect
  • MultiEdit
  • Clipboard
  • Process
  • Notification
  • Registry

The interactive security report will load automatically.