Critical-risk tools in GCP MCP Server
51 of the 295 tools in GCP MCP Server are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
gcp_agent_delete_appDestructiveDelete an Agent Builder application
-
gcp_agent_delete_data_storeDestructiveDelete a data store
-
gcp_agent_delete_endpointDestructiveDelete a Vertex AI endpoint
-
gcp_agent_delete_modelDestructiveDelete a Vertex AI model
-
gcp_agent_delete_reasoning_engineDestructiveDelete a Reasoning Engine
-
gcp_appengine_delete_serviceDestructiveDelete an App Engine service
-
gcp_appengine_delete_versionDestructiveDelete an App Engine version
-
gcp_ar_delete_packageDestructiveDelete a package from a repository
-
gcp_ar_delete_repositoryDestructiveDelete an Artifact Registry repository
-
gcp_ar_delete_versionDestructiveDelete a package version
-
gcp_bq_delete_datasetDestructiveDelete a BigQuery dataset
-
gcp_bq_delete_tableDestructiveDelete a BigQuery table
-
gcp_compute_delete_diskDestructiveDelete a persistent disk
-
gcp_compute_delete_instanceDestructiveDelete a VM instance
-
gcp_compute_delete_snapshotDestructiveDelete a disk snapshot
-
gcp_compute_detach_diskDestructiveDetach a disk from a VM instance
-
gcp_dns_delete_managed_zoneDestructiveDelete a managed zone
-
gcp_dns_delete_record_setDestructiveDelete a DNS record set via a change
-
gcp_firestore_delete_documentDestructiveDelete a Firestore document
-
gcp_functions_deleteDestructiveDelete a Cloud Function
-
gcp_gke_delete_clusterDestructiveDelete a GKE cluster
-
gcp_gke_delete_node_poolDestructiveDelete a node pool from a GKE cluster
-
gcp_iam_delete_custom_roleDestructiveDelete a custom IAM role
-
gcp_iam_delete_service_accountDestructiveDelete a service account
-
gcp_iam_delete_service_account_keyDestructiveDelete a service account key
-
gcp_iam_remove_iam_bindingDestructiveRemove an IAM binding from the project policy
-
gcp_lb_delete_backend_serviceDestructiveDelete a backend service
-
gcp_lb_delete_forwarding_ruleDestructiveDelete a forwarding rule
-
gcp_lb_delete_target_poolDestructiveDelete a target pool
-
gcp_logging_delete_logDestructiveDelete all entries for a log name
-
gcp_logging_delete_sinkDestructiveDelete a logging sink
-
gcp_monitoring_delete_alert_policyDestructiveDelete an alert policy
-
gcp_monitoring_delete_uptime_checkDestructiveDelete an uptime check
-
gcp_pubsub_delete_subscriptionDestructiveDelete a Pub/Sub subscription
-
gcp_pubsub_delete_topicDestructiveDelete a Pub/Sub topic
-
gcp_rm_delete_projectDestructiveDelete (schedule for deletion) a GCP project
-
gcp_run_delete_revisionDestructiveDelete a Cloud Run revision
-
gcp_run_delete_serviceDestructiveDelete a Cloud Run service
-
gcp_secrets_deleteDestructiveDelete a secret
-
gcp_services_disableDestructiveDisable a GCP API service for the project
-
gcp_sql_delete_databaseDestructiveDelete a database from a Cloud SQL instance
-
gcp_sql_delete_instanceDestructiveDelete a Cloud SQL instance
-
gcp_sql_delete_userDestructiveDelete a user from a Cloud SQL instance
-
gcp_storage_delete_bucketDestructiveDelete a Cloud Storage bucket
-
gcp_storage_delete_objectDestructiveDelete an object from a bucket
-
gcp_vpc_delete_firewallDestructiveDelete a firewall rule
-
gcp_vpc_delete_networkDestructiveDelete a VPC network
-
gcp_vpc_delete_routeDestructiveDelete a route
-
gcp_vpc_delete_subnetworkDestructiveDelete a subnetwork
-
gcp_vpc_release_addressDestructiveRelease a static IP address
-
gcp_billing_update_project_billing_infoFinancialLink/unlink a project to a billing account
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.