Critical-risk tools in FlowDot MCP Server
26 of the 207 tools in FlowDot MCP Server are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
browser_actDestructivePerform one UI action. action ∈ click | double_click | right_click | type | clear | press_key | scroll | hover | wait | upload_file | select_option | navigate. target = element ...
-
cancel_executionDestructiveCancel a running workflow execution. Only works on executions with status
-
delete_agent_characterDestructivePermanently delete an agent character. Requires confirm: true. This is irreversible — any voice-call session in flight will fail with a 404 on its character lookup.
-
delete_appDestructivePermanently delete an app. This action cannot be undone. The app and all its associated data (comments, votes, etc.) will be removed. Existing clones of the app will continue t...
-
delete_app_fileDestructiveDelete a file from a multi-file FlowDot app. Permanently removes the file from the app. This action cannot be undone. Note: Deleting the entry point file will require you to s...
-
delete_connectionDestructiveRemove a connection between two nodes in a workflow.
-
delete_custom_nodeDestructiveDelete a custom node. This action cannot be undone.
-
delete_goalDestructivePermanently delete a goal and all its tasks and milestones.
-
delete_goal_milestoneDestructiveDelete a milestone from a goal.
-
delete_goal_taskDestructiveDelete a task from a goal.
-
delete_imageDestructiveDelete one of your uploaded images by id. Removes the stored file and frees the storage it used. Only your own images can be deleted.
-
delete_input_presetDestructiveDelete an input preset. You can only delete presets you created.
-
delete_knowledge_categoryDestructiveDelete a knowledge base category. Documents in the category will become uncategorized (not deleted).
-
delete_knowledge_documentDestructivePermanently delete a document from your knowledge base. This removes the file and all associated chunks/embeddings.
-
delete_nodeDestructiveDelete a node from a workflow. This also removes all connections to/from the node.
-
delete_recipeDestructivePermanently delete an agent recipe. This action cannot be undone.
-
delete_recipe_stepDestructiveDelete a step from a recipe. References to this step will need to be updated.
-
delete_recipe_storeDestructiveDelete a store from a recipe. Steps using this store will need to be updated.
-
delete_workflowDestructivePermanently delete a workflow. This action cannot be undone. Only the workflow owner can delete it.
-
email_deleteDestructiveMove an email message to trash. Subject to mailbox grant permissions. This is a soft delete (trash), not permanent.
-
mcp__flowdot__delete_agent_toolkitDestructiveDelete a toolkit permanently. WARNING: This cannot be undone. All tools, installations, and related data will be deleted.
-
mcp__flowdot__delete_toolkit_toolDestructiveDelete a tool from a toolkit. WARNING: This cannot be undone. The tool will be permanently removed.
-
mcp__flowdot__uninstall_toolkitDestructiveUninstall a toolkit from your account. Removes the installation and credential mapping (toolkit itself remains available).
-
panic_clearDestructiveClear an active emergency stop for your account. Requires
-
revoke_kb_accessDestructiveRevoke one of YOUR Knowledge-Base grants by its grant id (get it from \
-
unlink_property_kb_sourceDestructiveRemove a Knowledge-Base source link from a property you own, by its link id (get the id from \
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.