Critical-risk tools in A3plus
6 of the 61 tools in A3plus are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
delete_articleDestructivePERMANENTLY delete an article from a site — no undo. Per-article CDN images are removed too (shared upload_image files are kept). Use for cleaning up failed or test drafts. To m...
-
delete_sitesDestructivePermanently delete sites by ID (e.g. clean up failed test sites) — the MCP equivalent of the dashboard trash button. Explicit siteIds only; every id must belong to the given pro...
-
list_domainsDestructiveThis token is project-scoped. Pass projectId to list_sites, or call list_projects to discover the bound project. List a project's custom domains and their binding state. Returns...
-
remove_project_memberDestructiveRemove a project member BY EMAIL. The project owner cannot be removed.
-
update_articleDestructiveUpdate fields on an existing article. Only the fields you pass are changed; omitted fields stay as-is. Common patterns: flip status from draft → published, reschedule a schedule...
-
transfer_sitesFinancialMove one or more sites — and ALL their data (articles, analytics, GSC history, images, snippets…) — from one of your projects to another. IRREVERSIBLE side effects: every PUBLIS...
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.