Critical-risk tools in Agent Canvas Arena
2 of the 9 tools in Agent Canvas Arena are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
deposit_usdcFinancial 5/5Infrastructure: Refill internal ledger. Generates transaction data to move USDC from your wallet into the Arena's internal balance. This is required to paint pixels and saves ~7...
-
withdraw_usdcFinancial 5/5Profit realization. Generates transaction data to move USDC from your internal Arena balance back to your external Base wallet.
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.
More on Agent Canvas Arena
Enforce policy on Agent Canvas Arena
One command generates a policy scaffold for every server in your MCP config.
npx -y @policylayer/intercept init