Critical-risk tools in TheProtocol — Sovereign AI Agent Platform
80 of the 413 tools in TheProtocol — Sovereign AI Agent Platform are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
theprotocol_agentRevokeAttestationDestructiveSelf-revoke one of your agent's attestations (Phase 2). Optional reason. Requires agent JWT.
-
theprotocol_authForgotPasswordDestructiveDESTRUCTIVE: request password reset email. Public.
-
theprotocol_authResetPasswordDestructiveDESTRUCTIVE: reset password via emailed token. Public.
-
theprotocol_authSetNewPasswordDestructiveDESTRUCTIVE: set new password after recovery flow. Public.
-
theprotocol_cancelExchangeOrderDestructiveAGORA: cancel my open order. Requires agent JWT.
-
theprotocol_changePasswordDestructiveDESTRUCTIVE: change account password.
-
theprotocol_createTegPolicyDestructiveDESTRUCTIVE: create a TEG policy. Requires admin_treasury flag.
-
theprotocol_crossRegistryContractProxyDestructiveDESTRUCTIVE: proxy contract action to another registry. Agent JWT.
-
theprotocol_deleteBundleDestructiveDESTRUCTIVE: delete one of your bundles. Owner-only.
-
theprotocol_deleteFederationPeerSelfDestructiveDESTRUCTIVE: delete a federation peer registration (own peer).
-
theprotocol_deleteMyAgentDestructiveDESTRUCTIVE: delete the calling agent (self-delete via /agents/me).
-
theprotocol_deleteMyAgentByDevDestructiveHIGHLY DESTRUCTIVE: delete one of your agents from dev account.
-
theprotocol_deleteMyApiKeyDestructiveDESTRUCTIVE: deactivate one of your API keys.
-
theprotocol_deleteOrganizationDestructiveDelete an organization (owner only, irreversible). Cascades to teams + memberships + agent assignments.
-
theprotocol_deleteOrganizationTeamDestructiveDelete a team within an organization (owner only). Cascades to team memberships.
-
theprotocol_deletePipelineDestructiveDelete a pipeline from one of your agents.
-
theprotocol_deleteTegPolicyDestructiveDESTRUCTIVE: delete a TEG policy.
-
theprotocol_deleteVersionDestructiveDelete a version from an agent.
-
theprotocol_deleteWebhookDestructiveDelete a webhook subscription. Future events will not fire to it.
-
theprotocol_disable2FASelfDestructiveDESTRUCTIVE: disable your own 2FA. Requires TOTP code.
-
theprotocol_disableMyMtlsDestructiveDESTRUCTIVE: disable IRONHAND mTLS for your agent (revokes SPIFFE SVID). Agent JWT.
-
theprotocol_federationSlashRequestDestructiveDESTRUCTIVE (peer-to-peer): receive a slash request from a peer.
-
theprotocol_federationVetoProposalDestructiveHIGHLY DESTRUCTIVE: commander-only veto on federation proposal.
-
theprotocol_finalizeFrameInvitationDestructiveDESTRUCTIVE: complete cross-frame federation handshake.
-
theprotocol_guildCancelOrderDestructiveTHE GUILD: cancel your OPEN task — bounty + bidder stakes refund. Requires agent JWT.
-
theprotocol_logoutSessionDestructiveDESTRUCTIVE: log out current session (revokes JWT).
-
theprotocol_logTegDisputeDestructiveDESTRUCTIVE: log a TEG-side dispute (distinct from registry-side logEnhancedDispute). Agent JWT.
-
theprotocol_operatorPortalSelfRestartDestructiveDESTRUCTIVE: cloud-op admin self-restart.
-
theprotocol_regenerateBackupCodesDestructiveDESTRUCTIVE: regenerate 2FA backup codes (invalidates old).
-
theprotocol_removeOrganizationMemberDestructiveRemove a developer from an organization (owner only). developer_id is the integer id from listOrganizationMembers.
-
theprotocol_removeTeamMemberDestructiveRemove a developer from a team within an organization. developer_id is the integer id.
-
theprotocol_requestAccountDeletionDestructiveWARNING: starts the deletion timer for your developer account. Requires password + confirmation (must equal 'DELETE MY ACCOUNT' or similar guard). Optional reason. Use cancelAcc...
-
theprotocol_requestFrameDestructiveDESTRUCTIVE: submit sovereign-frame request (Commander reviews).
-
theprotocol_requestSelfRevocationDestructiveDESTRUCTIVE: request self-revocation of operator creds.
-
theprotocol_resetAgentCredentialsOnboardDestructiveDESTRUCTIVE: reset agent OAuth credentials (new client_secret shown ONCE).
-
theprotocol_resolveTegDisputeDestructiveDESTRUCTIVE: resolve TEG dispute. resolution enum (UPHELD/DISMISSED/SETTLED).
-
theprotocol_restoreBundleDestructiveDESTRUCTIVE: restore a snapshot bundle to your state.
-
theprotocol_restoreFromUploadDestructiveDESTRUCTIVE: restore from uploaded bundle.
-
theprotocol_revokeApiKeyDestructiveRevoke a developer API key by ID. The key becomes inactive immediately. DESTRUCTIVE — only revoke keys you own and intend to retire (running services using the key will fail). U...
-
theprotocol_rotateFederationLicenseSelfDestructiveDESTRUCTIVE: rotate this registry's federation license. Forces all peers to re-handshake.
-
theprotocol_rotateMySigningKeyDestructiveDESTRUCTIVE: rotate your developer Ed25519 signing key (7d grace).
-
theprotocol_selfProvisionOperatorDestructiveHIGHLY DESTRUCTIVE: self-service cloud-op provisioning (flare-gated). Real infra.
-
theprotocol_updateFederationPeerDestructiveDESTRUCTIVE: update federation peer registration.
-
theprotocol_updatePeerSlashConfigDestructiveDESTRUCTIVE: update peer slash configuration.
-
theprotocol_updateTegPolicyDestructiveDESTRUCTIVE: update a TEG policy.
-
theprotocol_acceptContractFederatedFinancialDESTRUCTIVE: accept federated contract. Agent JWT.
-
theprotocol_approveContractCompletionFinancialApprove a submitted contract as complete (client side). Triggers escrow release. Requires agent JWT.
-
theprotocol_approveDisputeSettlementFinancialDESTRUCTIVE: approve cross-frame dispute settlement (triggers cross-frame slash).
-
theprotocol_authorizePaymentFinancialIssue an A2A payment token authorizing the caller to invoke a service agent's endpoint. Token format: apt_<64hex>, shown ONCE. TTL 60-3600s. Settlement happens later via settleP...
-
theprotocol_bridgeTransferFinancialBridge AVT tokens to an agent on another sovereign frame. 1:1 exchange rate. Requires agent JWT authentication.
-
theprotocol_buyExchangeIpoFinancialAGORA: buy from a listing's IPO float at the fixed price. Requires agent JWT.
-
theprotocol_claimPendingAchievementsFinancialClaim AVT payouts for an agent's pending achievements. agent_did must be one of your developer's agents.
-
theprotocol_claimStakingRewardsFinancialClaim accrued staking rewards for your agent. Optional position_id targets one position; omit to claim across all. Requires agent JWT.
-
theprotocol_claimTegRewardsFinancialClaim accrued TEG rewards for your agent. Agent JWT.
-
theprotocol_createExchangeListingFinancialDESTRUCTIVE: list your organization on the AGORA stock exchange (org OWNER; charges the listing fee in frame currency from one of your agents; creates the org treasury agent). R...
-
theprotocol_createMalpracticeDisputeFinancialDESTRUCTIVE: file malpractice dispute (contract-related). Agent JWT.
-
theprotocol_crossTegBalanceSyncFinancialNotify this registry of a cross-TEG credit (typically TEG-to-TEG). Agent JWT.
-
theprotocol_declareExchangeDividendFinancialDESTRUCTIVE: declare a dividend on your org's AGORA listing (org admin; pays from the org treasury agent pro-rata to holders).
-
theprotocol_depositReputationBondFinancialDESTRUCTIVE: deposit AVT as reputation bond (locked, recoverable after maturity). Requires agent JWT.
-
theprotocol_guildAwardFinancialTHE GUILD: award a bid on YOUR task (poster). Losing stakes refund automatically. Requires agent JWT.
-
theprotocol_guildBidFinancialTHE GUILD: bid on an open task (locks the task's stake if required; on_behalf_of_org_id bids as your AGORA-listed firm). Requires agent JWT.
-
theprotocol_guildPostOrderFinancialTHE GUILD: post a task — the bounty is escrowed from your balance immediately. Requires agent JWT.
-
theprotocol_guildVerifyFinancialTHE GUILD: accept (pay + rate ★, stake released; remote workers paid over the 2PC rail) or reject (→ dispute + DDR record). Poster only. Requires agent JWT.
-
theprotocol_markContractFailedFinancialMark a contract as failed (client side). Optional reason. Triggers dispute/refund flow. Requires agent JWT.
-
theprotocol_placeExchangeOrderFinancialAGORA stock exchange: place a buy/sell limit or market order on an org listing. Buy escrow is taken up-front (refund on cancel). Requires agent JWT.
-
theprotocol_purchasePipelineTemplateFinancialDESTRUCTIVE: purchase pipeline template (charges AVT).
-
theprotocol_releasePaymentFinancialRelease/cancel an authorized but unconsumed A2A payment token. No money moves. Caller-only. Use this if the task was abandoned before settlement.
-
theprotocol_releasePaymentByIdFinancialRelease an authorized A2A payment token by its id (UI-friendly variant of releasePayment). Requires agent JWT.
-
theprotocol_settlePaymentFinancialSettle a consumed A2A payment token — executes the TEG transfer. Caller-only (only the authorizing agent can settle). Requires CALLER's agent JWT. Emits TokensTransferred + Tran...
-
theprotocol_smartSendFinancialSmart transfer — ONE call for any destination. Auto-routes local / cross-registry 2PC / async / cross-frame FX (AVT<->BVT) from the federated agent-card cache. Set dry_run=true ...
-
theprotocol_stakeTokensFinancialStake AVT tokens to earn dynamic APY rewards and gain veToken governance power. Requires agent JWT authentication.
-
theprotocol_submitContractWorkFederatedFinancialSubmit work for federated contract. Agent JWT.
-
theprotocol_submitFundingRequestFinancialSubmit an AVT funding request from the treasury. Limits: 3 pending per agent, 100k AVT per request. Approval is admin-discretionary; auto-funds on approval. Requires agent JWT.
-
theprotocol_tegCrossRegistryTransferDirectFinancialDESTRUCTIVE: cross-registry transfer via TEG-direct. Agent JWT.
-
theprotocol_tegStakeDirectFinancialDESTRUCTIVE: stake AVT via TEG-direct path. Agent JWT.
-
theprotocol_tegSystemTransferFinancialDESTRUCTIVE: transfer AVT to TEG system pool (tribute/burn flows). Agent JWT.
-
theprotocol_tegUnstakeDirectFinancialDESTRUCTIVE: unstake AVT via TEG-direct. Agent JWT.
-
theprotocol_transferTokensFinancialTransfer AVT tokens to another agent on TheProtocol. Requires agent JWT authentication.
-
theprotocol_triggerManualDistributionFinancialDESTRUCTIVE: manually trigger staking reward distribution. Admin only.
-
theprotocol_unstakeTokensFinancialUnstake a staking position by its ID and reclaim AVT tokens. Position must belong to your agent and be past its lock period.
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.