Critical-risk tools in Appaloft
37 of the 358 tools in Appaloft are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
account_deleteDestructiveRun account.delete through the Appaloft application operation catalog. Shared with HTTP/API.
-
account_sessions_revokeDestructiveRun account.sessions.revoke through the Appaloft application operation catalog. Shared with HTTP/API.
-
certificates_deleteDestructiveRun certificates.delete through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
certificates_revokeDestructiveRun certificates.revoke through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
connections_revokeDestructiveRun connections.revoke through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
control_plane_portability_artifacts_deleteDestructiveRun control-plane-portability.artifacts.delete through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
credentials_delete_sshDestructiveRun credentials.delete-ssh through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
dependency_resources_deleteDestructiveRun dependency-resources.delete through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
deployments_cancelDestructiveRun deployments.cancel through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
deployments_force_redeployDestructiveRun deployments.force-redeploy through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
domain_bindings_deleteDestructiveRun domain-bindings.delete through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
domain_bindings_delete_checkDestructiveRead domain-bindings.delete-check through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
operator_work_cancelDestructiveRun operator-work.cancel through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
organizations_deleteDestructiveRun organizations.delete through the Appaloft application operation catalog. Shared with HTTP/API.
-
organizations_remove_memberDestructiveRun organizations.remove-member through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
preview_environments_deleteDestructiveRun preview-environments.delete through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
projects_deleteDestructiveRun projects.delete through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
projects_delete_checkDestructiveRead projects.delete-check through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
resources_deleteDestructiveRun resources.delete through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
resources_delete_checkDestructiveRead resources.delete-check through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
resources_reset_healthDestructiveRun resources.reset-health through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
resources_secrets_deleteDestructiveRun resources.secrets.delete through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
sandbox_credentials_revokeDestructiveRun sandbox-credentials.revoke through the Appaloft application operation catalog. Shared with HTTP/API.
-
sandbox_files_removeDestructiveRun sandbox-files.remove through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
sandbox_ports_revokeDestructiveRun sandbox-ports.revoke through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
sandbox_snapshots_deleteDestructiveRun sandbox-snapshots.delete through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
sandbox_templates_deleteDestructiveRun sandbox-templates.delete through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
sandboxes_agents_runs_cancelDestructiveRun sandboxes.agents.runs.cancel through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
sandboxes_candidate_previews_deleteDestructiveRun sandboxes.candidate-previews.delete through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
sandboxes_source_artifacts_deleteDestructiveRun sandboxes.source-artifacts.delete through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
scheduled_tasks_deleteDestructiveRun scheduled-tasks.delete through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
servers_deleteDestructiveRun servers.delete through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
servers_delete_checkDestructiveRead servers.delete-check through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
source_links_deleteDestructiveRun source-links.delete through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
storage_volumes_deleteDestructiveRun storage-volumes.delete through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
tunnels_revokeDestructiveRun tunnels.revoke through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
organizations_transfer_ownerFinancialRun organizations.transfer-owner through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.