Critical-risk tools in Thinkific MCP Server
13 of the 109 tools in Thinkific MCP Server are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
delete_categoryDestructiveDelete a category from the Thinkific site.
-
delete_couponDestructiveDelete a coupon.
-
delete_groupDestructiveDelete a group from the Thinkific site.
-
delete_instructorDestructiveDelete an instructor profile.
-
delete_promotionDestructiveDelete a promotion.
-
delete_site_scriptDestructiveDelete a site script.
-
delete_userDestructiveDelete a user from the Thinkific site.
-
gql_bulk_remove_users_from_groupsDestructiveBulk remove multiple users from multiple groups (GraphQL).
-
remove_group_analystDestructiveRemove a user as an analyst from a group.
-
remove_products_from_categoryDestructiveRemove products from a category (collection membership).
-
create_external_orderFinancialCreate an external order for a user (for purchases made outside Thinkific).
-
purchase_external_orderFinancialRecord a purchase transaction for an external order.
-
refund_external_orderFinancialRefund an external order.
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.