Critical-risk tools in AIquila — Nextcloud MCP Server
47 of the 295 tools in AIquila — Nextcloud MCP Server are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
bulk_file_operationsDestructiveExecute multiple file operations (move, copy, delete) sequentially in a single call. Returns per-item results.
-
circles_deleteDestructiveDelete a circle/team. Requires owner privileges.
-
circles_remove_memberDestructiveRemove a member from a circle/team. Use circles_list_members to get the memberId. Requires moderator privileges or higher.
-
clear_out_of_officeDestructiveClear a user
-
clear_user_status_messageDestructiveClear the current user
-
deleteDestructiveDelete a file or folder from Nextcloud
-
delete_all_form_submissionsDestructiveDelete every submission for a form. The form itself is kept. This cannot be undone.
-
delete_all_notificationsDestructiveDelete all notifications for the current user
-
delete_announcementDestructiveDelete an announcement by its ID. Requires the configured Nextcloud user to be an admin.
-
delete_bookmarkDestructiveDelete a bookmark by its ID. This action is irreversible.
-
delete_bookmark_folderDestructiveDelete a bookmark folder and all its contents. This action is irreversible.
-
delete_bookmark_tagDestructiveDelete a bookmark tag. The tag will be removed from all bookmarks.
-
delete_contactDestructiveDelete a contact from a Nextcloud address book by UID. This action is irreversible.
-
delete_coworkerDestructiveDelete a coworker and its run history.
-
delete_eventDestructiveDelete a calendar event from Nextcloud by UID. This action is irreversible.
-
delete_feedDestructiveDelete (unsubscribe from) a feed and all its items.
-
delete_formDestructivePermanently delete a form and all of its submissions. This cannot be undone.
-
delete_form_optionDestructiveDelete an option from a choice question.
-
delete_form_questionDestructiveDelete a question from a form.
-
delete_form_shareDestructiveRevoke a form share.
-
delete_form_submissionDestructiveDelete a single submission by ID.
-
delete_mapDestructiveDelete a custom map. This action is irreversible.
-
delete_map_deviceDestructiveDelete a GPS tracking device and all its location points. This action is irreversible.
-
delete_map_favoriteDestructiveDelete a map favorite by its ID. This action is irreversible.
-
delete_news_folderDestructiveDelete a News folder and all feeds it contains.
-
delete_noteDestructiveDelete a note by its ID.
-
delete_pollDestructivePermanently delete a poll. This cannot be undone.
-
delete_poll_commentDestructiveDelete one of your poll comments by comment ID.
-
delete_poll_optionDestructiveDelete an option from a poll by option ID.
-
delete_poll_shareDestructiveRevoke a poll share by its token (obtained from list_poll_shares or add_poll_share).
-
delete_projectDestructiveDelete an AIquila project. Associated paths are removed and conversations referencing it are unlinked.
-
delete_recipeDestructiveDelete a recipe from Nextcloud Cookbook. This removes the entire recipe folder including images. This action is irreversible.
-
delete_shareDestructiveDelete a share in Nextcloud
-
delete_taskDestructiveDelete a task from Nextcloud Tasks by UID. This action is irreversible.
-
delete_terms_of_serviceDestructiveDelete a single terms of service entry by its id (see get_terms_of_service). Requires
-
delete_text_workspaceDestructiveDelete the Text workspace file (Readme.md) for a folder. The folder itself is kept. No-op if the folder has no workspace.
-
empty_trashDestructivePermanently delete all files in the trash (cannot be undone)
-
mail_delete_messageDestructiveDelete an email message by ID. This typically moves it to trash.
-
photos_delete_albumDestructiveDelete a photo album. This only removes the album — the underlying files are not deleted.
-
remove_project_pathDestructiveRemove a file or directory path from an AIquila project.
-
remove_user_from_groupDestructiveRemove a Nextcloud user from a group. Requires admin privileges
-
reset_map_photo_coordsDestructiveRemove GPS coordinates from one or more photos.
-
reset_registration_settingDestructiveReset a Nextcloud Registration app setting to its default by deleting the stored value.
-
reset_terms_signaturesDestructiveReset ALL users
-
talk_delete_messageDestructiveDelete a message from a Talk conversation.
-
talk_remove_participantDestructiveRemove a participant from a Talk conversation by their attendee ID (from list_participants).
-
uninstall_appDestructiveRemove a Nextcloud app via occ app:remove
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.