Critical-Risk MCP Tools
Critical-risk MCP tools destroy data or move money. Both actions are irreversible, and both can be completed in a single call. These tools share a policy requirement: blocked by default, enabled only with human approval and per-transaction limits.
Attacks targeting critical-risk tools
Named attack patterns where tools at this severity have produced real incidents. Each links to the full case and the defensive policy.
Servers with critical-risk tools
Showing 50 of 9977 servers. Each server link opens its capability-level browse; each tool opens its profile with the recommended policy.
- GoHighLevel MCP Server 449 critical-risk tools
- Binance MCP Server 197 critical-risk tools
- Pfsense 178 critical-risk tools
- Mcp 138 critical-risk tools
- Mcp Server 138 critical-risk tools
- Huly 123 critical-risk tools
- AdButler 114 critical-risk tools
- Discord 107 critical-risk tools
- GPT 5 5 x402 Low Cost Agent Tools 86 critical-risk tools
- WordPress MCP Server 81 critical-risk tools
- TheProtocol — Sovereign AI Agent Platform 81 critical-risk tools
- Aibtc 80 critical-risk tools
- Mealie MCP Server 79 critical-risk tools
- CloudStack MCP Server 78 critical-risk tools
- Storyblok MCP Server 73 critical-risk tools
- Bybit MCP Server 70 critical-risk tools
- n8n MCP Server 63 critical-risk tools
- HubSpot MCP Server 62 critical-risk tools
- Gapup Mcp 62 critical-risk tools
- MikroTik Cursor MCP 60 critical-risk tools
- Linode MCP Server 58 critical-risk tools
- Databricks MCP Server 57 critical-risk tools
- GCP MCP Server 56 critical-risk tools
- Bybit 55 critical-risk tools
- Todoist MCP Server 53 critical-risk tools
- Shopify Graphql 53 critical-risk tools
- Marketo MCP Server 52 critical-risk tools
- Pipedrive MCP Server 52 critical-risk tools
- HubSpot MCP 51 critical-risk tools
- QuintaDB 51 critical-risk tools
- Crow 51 critical-risk tools
- Tenzro Ledger MCP 51 critical-risk tools
- OPNsense MCP Server 50 critical-risk tools
- Hiveagent 50 critical-risk tools
- Trello 50 critical-risk tools
- Fortimanager 50 critical-risk tools
- Yaver 49 critical-risk tools
- Plane 48 critical-risk tools
- AIquila — Nextcloud MCP Server 47 critical-risk tools
- Clickup 47 critical-risk tools
- Mcp Dev 47 critical-risk tools
- Ebay 46 critical-risk tools
- Polymarket MCP Server 46 critical-risk tools
- Waiaas 46 critical-risk tools
- Truenas 46 critical-risk tools
- Gmail MCP Server 45 critical-risk tools
- ServiceTitan MCP Server 45 critical-risk tools
- VaultPilot MCP 45 critical-risk tools
- Ghl 44 critical-risk tools
- Sanka MCP Server 44 critical-risk tools
See all tools in destructive · financial.
Other risk levels
Frequently asked questions
What makes a tool critical risk?
Critical-risk MCP tools perform irreversible operations. Destructive tools permanently delete or destroy resources. Financial tools move real money. Once called, there is no undo at the MCP layer. PolicyLayer classifies these tools together because they share the same policy recommendation: block by default, require human approval with per-transaction limits before enabling.
How should I enforce policy on critical-risk tools?
Default-deny is the baseline. Destructive operations require explicit human approval at the transport layer. Financial operations need per-transaction spending caps, daily budgets, and recipient allowlists. The PolicyLayer policy engine supports all four primitives (deny, require_approval, spend caps, allowlists).
Which MCP servers expose critical-risk tools?
Thousands. Any server that edits state (CRMs, databases, filesystems) has destructive operations. Payment-rail servers (Stripe, crypto wallets, banking APIs) have financial operations. The risk is concentrated in the critical category, not the server.
What attacks target critical-risk tools?
Destructive action autonomy is the most-cited incident class (Amazon Kiro, Replit/SaaStr). Privilege escalation via admin-only tools, runaway tool loops, and data exfiltration via tool chaining all overlap. See the MCP Attack Database for the full catalogue with real cases and defensive policies.
How is risk score calculated?
PolicyLayer runs every discovered MCP tool through a classifier that assigns a category (Read/Write/Execute/Destructive/Financial/Other) and a 1–5 severity score. Destructive and Financial tools receive the highest scores. The classifier is proprietary; its output powers this catalogue.