Critical-risk tools in CoWork OS
17 of the 342 tools in CoWork OS are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
cancel_agentDestructiveCancel a descendant child agent task. This tool only works for tasks spawned by the current task (descendants).
-
cancel_video_generation_jobDestructiveCancel an in-progress video generation job. Not all providers support cancellation; an error will be returned for unsupported providers.
-
cloud_sandbox_deleteDestructiveDelete a cloud sandbox and free resources.
-
delete_fileDestructiveDelete a file (requires user approval)
-
disable_macos_launch_agentsDestructiveUnload and move matching user LaunchAgent plists into ~/Library/LaunchAgents.disabled-by-cowork.
-
domain_dns_deleteDestructiveDelete a DNS record from a domain.
-
google-workspace.calendar_event_deleteDestructiveDelete a Google Calendar event. Confirm with the user before calling.
-
google-workspace.slides_delete_slideDestructiveDelete a slide from a Google Slides presentation. Confirm with the user before calling.
-
google-workspace.tasks_clear_completedDestructiveClear completed tasks from a Google Tasks task list. Confirm with the user before calling.
-
google-workspace.tasks_deleteDestructiveDelete a Google Tasks task. Confirm with the user before calling.
-
google-workspace.tasks_lists_deleteDestructiveDelete a Google Tasks task list. Confirm with the user before calling.
-
kg_delete_edgeDestructiveDelete a relationship (edge) from the knowledge graph.
-
kg_delete_entityDestructiveDelete an entity and all its relationships and observations from the knowledge graph.
-
skill_deleteDestructiveDelete a skill. Only managed and workspace skills can be deleted (not bundled).
-
supermemory_forgetDestructiveForget a Supermemory entry by ID or exact content. Use this when an external memory is outdated or wrong.
-
domain_registerFinancialRegister a domain name. Requires user approval before proceeding.
-
x402_fetchFinancialFetch a URL with automatic x402 payment. If the server returns 402, signs a payment and retries.
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.