Critical-risk tools in agentView
7 of the 57 tools in agentView are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
delete_assetDestructiveDeletes one or more assets. Displays referencing deleted assets will show broken images. Requires authentication with at least content_only scope.
-
delete_data_slotDestructivePermanently deletes a data slot. Display HTML fetching its readUrl will receive 404 after deletion. Cannot be undone. Supply group_id to delete a group slot; omit for personal s...
-
delete_displayDestructivePermanently deletes a display and all its associated content. This action cannot be undone. Use this only when the user explicitly confirms they want to remove the display. Requ...
-
delete_organizationDestructivePermanently deletes an organization, releasing all its displays and removing all members. Only the owner can delete. This cannot be undone. Requires admin scope.
-
logoutDestructiveClears the cached login from this MCP session (does not revoke the underlying token). Use when the user wants to sign out or switch accounts.
-
remove_display_from_orgDestructiveRemoves a display from an organization, clearing its group assignment and all display grants. The display becomes unassigned. Requires admin scope and admin or owner role.
-
revoke_api_keyDestructivePermanently revokes an API key. This is irreversible — the key will immediately stop working. Requires admin scope.
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.