Risk Browse

MCP tool risk levels

PolicyLayer classifies every MCP tool in the catalogue by severity. Browse by level to see which tools share the same blast radius, which attacks target each class, and what policy pattern defends against them. For the full context, start with the MCP Security reference.

Severity is derived from the tool's capability class. Destructive and financial operations share critical severity because both produce irreversible harm. Execute operations score high because side effects reach beyond the immediate call. Read and write operations get lower scores, but each still has documented attack surface.

Browse by capability

Prefer capability browse? Each category maps to specific behaviour patterns and has its own recommended policy approach.

// GET IN TOUCH

Have a question or want to learn more? Send us a message.

Message sent.

We'll get back to you soon.