Critical-risk tools in Enterprise-Multi-Agent-Engine
28 of the 262 tools in Enterprise-Multi-Agent-Engine are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
delete_apiDestructivedelete_api
-
delete_api_groupDestructiveDelete an API group by GUID.
-
delete_api_parameterDestructivedelete_api_parameter
-
delete_app_storeDestructiveDelete a Public Data store.
-
delete_app_store_methodDestructiveDelete a Public Data method.
-
delete_app_store_propertyDestructiveDelete a Public Data property.
-
delete_bounded_contextDestructiveDelete a bounded context by GUID; dependencies are never cascade-deleted.
-
delete_componentDestructivedelete_component
-
delete_component_eventDestructivePermanently delete any component event (Load, Update, or Element).
-
delete_component_propertyDestructivePermanently delete a component property.
-
delete_component_stateDestructivePermanently delete a component state.
-
delete_condition_fieldDestructiveDelete one Condition field record (upstream delete_condition).
-
delete_design_systemDestructiveDelete a Design System.
-
delete_design_system_colorDestructiveDelete a **Custom** color only.
-
delete_design_system_componentDestructiveDelete a Design System component variant.
-
delete_elementDestructiveDelete element.
-
delete_event_operationDestructiveDelete one operation. Destructive.
-
delete_javascript_functionDestructivePermanently delete a Javascript function from the component.
-
delete_javascript_function_parameterDestructiveDelete a Javascript function parameter.
-
delete_layoutDestructivedelete_layout
-
delete_microserviceDestructiveBackward-compatible alias for microservice_delete.
-
delete_operation_groupDestructivedelete_operation_group
-
delete_pageDestructivedelete_page
-
delete_productDestructiveDelete a product by its GUID.
-
invalidate_app_graph_cacheDestructiveDrop cached app catalog graph after catalog mutations.
-
invalidate_component_graph_cacheDestructiveDrop cached component graph after mutations so next call re-syncs from upstream.
-
microservice_deleteDestructiveOfficial upstream microservice delete service.
-
remove_api_from_componentDestructiveRemove an API service binding from the component.
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.