Critical-risk tools in Hermoso
84 of the 896 tools in Hermoso are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
answer_google_business_questionDestructivePost the business’s answer to a public question on the brand’s Google Business Profile listing, or delete the answer already there. THIS IS AN UPSERT — one answer per account, s...
-
apple_ads_change_historyDestructiveWho changed what on this Apple Ads account, and when. Call it with start and/or end to get one row per TRANSACTION GROUP — a single user action that may have touched several fie...
-
associate_linkedin_conversion_campaignsDestructiveAssociate LinkedIn campaigns with a conversion rule — or detach them with remove:true. THIS IS WHAT MAKES A CONVERSION COUNT: LinkedIn only attributes a conversion to campaigns ...
-
cancel_openai_ads_audience_operationDestructiveCancel an accepted ADD or REMOVE on a ChatGPT Ads custom audience BEFORE its membership changes begin. ChatGPT Ads refuses once the operation is already applying changes, and th...
-
cancel_scheduledDestructiveRemove a queued post before it goes out. Get the id from list_scheduled. Only works while it is still queued — something already published cannot be unsent (use manage_meta_post...
-
cancel_stripe_subscriptionDestructiveCancel a Stripe subscription: at the end of the current period by default (the customer keeps access until then), or immediately:true to end it now. ALWAYS needs confirm:true, t...
-
clear_sheet_rangeDestructiveEmpty a range of cells in a Google Sheet, leaving the rows themselves in place. DESTRUCTIVE: call it WITHOUT confirm first and nothing is cleared — you get back the real number ...
-
create_analytics_custom_dimensionDestructiveRegister an event parameter the site ALREADY SENDS as a custom dimension, so reports can break down by it (plan tier, content category, logged-in state…). TWO THINGS TO TELL THE...
-
create_openai_ads_campaignDestructiveBuild a campaign on the connected ChatGPT Ads account — the ads that appear below ChatGPT answers. ALWAYS created PAUSED at every level, with no override: it spends NOTHING unti...
-
delete_analytics_key_eventDestructiveREMOVE A KEY EVENT — the reverse of create_analytics_key_event, and note the ASYMMETRY with custom dimensions: a key event really can be DELETED, where a custom dimension can on...
-
delete_apple_ads_objectDestructiveDelete an Apple Ads campaign, ad group, keyword, negative keyword, ad, creative, asset, location group or budget order. Requires confirm:true, and optionally confirmName echoed ...
-
delete_bluesky_postDestructivePERMANENTLY delete one of the connected Bluesky account
-
delete_brandDestructivePERMANENTLY delete a profile and EVERYTHING in it — brand details, memory, swipefile, Library creations, generated assets, avatars, skills, playbooks, chats — and disconnect its...
-
delete_creatorDestructiveRemove a saved creator from this workspace’s cast by id (from list_creators). Records a cross-device delete so they don’t reappear on the user’s other devices. It only drops the...
-
delete_dm_automationDestructiveDelete one automation by id on any channel. Nothing further is sent by it; messages already sent stay; on X the event subscription is removed when no rule needs it. To pause ins...
-
delete_drive_fileDestructiveDelete a Drive file. By default it goes to Trash (recoverable); pass permanent:true to delete it forever. Pass fileId (from list_drive_files) + confirm:true. Irreversible when p...
-
delete_google_ads_objectDestructivePERMANENTLY remove a Google Ads object. Google has no HTTP delete — removal is a
-
delete_google_business_postDestructiveRemove a Post from the brand’s Google Business Profile listing. This takes it off Google Search and Maps immediately and CANNOT be undone — confirm with the user first. Pass the...
-
delete_instagram_dm_automationDestructiveDelete one automation by id. Nothing further is sent by it; DMs already sent stay. To pause instead, save it with enabled:false. Free.
-
delete_linkedin_ads_objectDestructiveDelete a LinkedIn campaign group, campaign or creative (level:
-
delete_linkedin_commentDestructiveRemove a comment from one of your LinkedIn company Page
-
delete_linkedin_lead_subscriptionDestructiveRemove a lead notification webhook (subscriptionId from list_linkedin_lead_subscriptions). Leads themselves are unaffected and stay readable; only the real-time delivery stops. ...
-
delete_merchant_data_sourceDestructiveDelete a data source (feed) from a Merchant Center account. CONFIRM-GATED and the heavier of the two deletes: without confirm:true nothing is deleted and it reports the feed plu...
-
delete_merchant_productDestructiveDelete a product from a Merchant Center feed. CONFIRM-GATED: without confirm:true nothing is deleted and it reports the real product it WOULD delete — title, price and availabil...
-
delete_messenger_marketing_campaignDestructiveDelete a marketing-message campaign. Irreversible: the first call names it and refuses; confirm:true deletes.
-
delete_meta_audienceDestructivePERMANENTLY delete a Meta custom audience or lookalike. Meta’s own warning:
-
delete_meta_catalogDestructivePERMANENTLY delete a product catalog. Meta does not let a catalog be removed from a business portfolio and then restored, and it cannot be transferred to another portfolio — the...
-
delete_meta_objectDestructivePERMANENTLY delete a campaign, ad set, or ad. Pass objectId (from list_meta_ads) + adAccountId. DELETING A CAMPAIGN ALSO DELETES EVERY AD SET AND AD UNDER IT, and deleting an ad...
-
delete_microsoft_ads_objectDestructivePERMANENTLY delete a Microsoft Advertising campaign, ad group, ad or keyword. This is a real delete — Microsoft removes the object and it stops being returned by every read, wit...
-
delete_microsoft_merchant_productDestructiveDelete one product offer from a Microsoft Merchant Center store. Pass productId as the FULLY QUALIFIED id (channel:contentLanguage:targetCountry:offerId), not the offerId. Call ...
-
delete_onedrive_fileDestructiveDelete a OneDrive item — it moves to the OneDrive recycle bin (recoverable there). Pass fileId (from list_onedrive_files) + confirm:true. Confirm the exact file with the user fi...
-
delete_openai_ads_lead_syncDestructiveDelete the lead-sync subscription: every lead form on the account stops delivering leads. confirm:true required.
-
delete_openai_ads_objectDestructiveRetire a ChatGPT Ads campaign, ad group or ad. THE OPENAI ADVERTISER API HAS NO DELETE — archiving is its only teardown, and OpenAI’s own guidance is
-
delete_openai_ads_spend_windowDestructiveDelete an active or scheduled spend-limit window before it ends — this REMOVES a spending ceiling. confirm:true required.
-
delete_pinterest_ads_objectDestructiveRetire a Pinterest campaign, ad group or ad. PINTEREST API v5 HAS NO DELETE for any of the three — ARCHIVED is its terminal state, and Pinterest’s own campaign docs call an arch...
-
delete_pinterest_boardDestructivePERMANENTLY delete a board AND EVERY PIN ON IT. This is the heaviest thing that can be done to a Pinterest account and there is no undelete. Call it WITHOUT confirm first: nothi...
-
delete_pinterest_pinDestructivePERMANENTLY delete a Pin. Pinterest has no undelete and no archive for one. Call it WITHOUT confirm first: nothing is deleted, and it answers with the Pin’s real title, its life...
-
delete_playbookDestructiveDelete a saved playbook by id (from list_playbooks). Records a cross-device delete so it does not come back on the next sync. Minor + re-creatable, so no confirm needed.
-
delete_reddit_ads_assetDestructivePermanently delete a creative asset from the Reddit asset library. Without confirm:true it deletes nothing and reports what the asset is; with it, the reply is the read-back (th...
-
delete_reddit_ads_audienceDestructivePermanently delete a Reddit custom audience. This is one of the very few things Reddit really deletes — campaigns, ad groups and ads are only ever archived — and it cannot be un...
-
delete_reddit_ads_objectDestructiveRemove a Reddit campaign, ad group or ad. REDDIT HAS NO DELETE VERB for any of the three — its whole Ads API has exactly four HTTP DELETE endpoints and none of them is a campaig...
-
delete_reddit_ads_saved_audienceDestructiveDelete a Reddit saved audience — the named, reusable targeting block ad groups point at. Reddit publishes NO delete verb for one (its whole Ads API has four, and this is not amo...
-
delete_search_console_siteDestructiveRemove a property from the connected Google account. THIS LOSES HISTORY: the account loses access to that property\
-
delete_search_console_sitemapDestructiveRemove a sitemap from a property. THIS DOES NOT REMOVE THOSE PAGES FROM GOOGLE\
-
delete_skillDestructiveDelete one of the workspace’s CUSTOM skills by id (from list_skills). Built-in skills/recipes can’t be deleted. Minor + re-creatable, so no confirm needed.
-
delete_snapchat_ads_objectDestructivePERMANENTLY DELETE a Snapchat campaign, ad squad or ad. Snapchat publishes a REAL delete verb at every tier — unlike TikTok, where removal is a status — so this is irreversible ...
-
delete_telegram_messageDestructivePERMANENTLY delete one message the bot posted to a Telegram chat. Call it WITHOUT confirm first: nothing is deleted and you get a sentence to show the user. There is deliberatel...
-
delete_threadDestructivePERMANENTLY delete one of the brand’s Threads posts. IRREVERSIBLE — Threads has no undelete. Call it WITHOUT confirm first: nothing is deleted, and it answers with the post’s re...
-
delete_tiktok_ads_audienceDestructiveDelete one or more TikTok custom audiences. IRREVERSIBLE: TikTok publishes no undelete, any Lookalike seeded from one loses its seed, every ad group targeting it stops using it,...
-
delete_tiktok_ads_commentDestructiveWarning: READ THIS BEFORE REACHING FOR IT: TikTok’s comment delete removes a comment YOUR OWN advertiser identity posted — your own reply. It CANNOT remove a comment left by a m...
-
delete_tiktok_ads_objectDestructiveRemove TikTok campaigns, ad groups or ads. TIKTOK HAS NO DELETE VERB — removal is modelled as a STATUS, exactly like Reddit — so this posts to the same route as set_tiktok_ads_s...
-
delete_tiktok_post_ad_authorizationDestructiveDelete the Spark-Ads authorization code for a post the authorized account owns. CONFIRM-GATED, and not because it spends: ads already built on the post keep running, but no NEW ...
-
delete_whatsapp_templateDestructivePERMANENTLY delete a WhatsApp message template. META DELETES EVERY LANGUAGE OF A NAME AT ONCE, which is a wider blast radius than most callers picture, so call it WITHOUT confir...
-
delete_x_ads_objectDestructivePERMANENTLY delete an X campaign, line item, promoted post or targeting criterion. X CASCADES AND PUBLISHES NO UNDO: deleting a campaign destroys its line items and their promot...
-
delete_x_postDestructivePermanently delete one of the connected account’s posts on X. This CANNOT be undone — confirm the exact post with the user first. Costs credits (X bills per API call). Needs X c...
-
delete_youtube_report_jobDestructiveStop a YouTube bulk reporting job. IRREVERSIBLE IN A WAY THAT IS EASY TO MISS: the job IS the history — deleting it discards every daily CSV it has accumulated, and a replacemen...
-
delete_youtube_videoDestructivePERMANENTLY delete a video from the connected YouTube channel. IRREVERSIBLE — YouTube has no trash and no undelete, and the video\
-
dismiss_microsoft_ads_recommendationsDestructiveDismiss Microsoft Advertising recommendations by id so Microsoft stops offering them. IT CANNOT SPEND and it changes nothing about what the account runs (it takes advice off the...
-
edit_timelineDestructiveCompose ANY edit or transition yourself; there is no preset list. Segments on an output timeline (later ones drawn on top; overlapping ones ARE the transition), each animated by...
-
forgetDestructiveDelete a saved Memory item by its id (from list_memory). Records a cross-device delete so it doesn’t come back. Minor + re-creatable (you can remember it again), so no confirm n...
-
leave_connectorDestructiveOn a connector that several teammates can contribute their OWN account to (see list_connectors — the row reports multiContributor), remove YOURS from this profile: your stored c...
-
link_tiktok_tto_videoDestructiveAsk a creator to link one of their public videos to a TikTok One campaign, or withdraw that request. THIS PUTS A NOTIFICATION IN A REAL PERSON’S TIKTOK INBOX, AND REPEATING IT I...
-
manage_bluesky_convoDestructiveAct on one Bluesky DM conversation. ACCEPT a message request \u2014 Bluesky holds DMs from people the account does not follow in a separate requests folder, and until one is acc...
-
meta_catalog_blast_radiusDestructiveRead what is INSIDE a product catalog — how many products, which product sets — and get the exact sentence describing what deleting it would destroy. Free and read-only. CALL TH...
-
microsoft_ads_recommendationsDestructiveWhat Microsoft Advertising ITSELF suggests changing on the account: budget raises, new keywords, broad-match widenings, conflicting negative keywords to remove, and responsive s...
-
moderate_meta_commentDestructiveModerate a comment on the brand’s Facebook or Instagram post. Prefer hide over delete — hiding is reversible and invisible to the commenter. Deleting is PERMANENT and requires c...
-
moderate_tiktok_ads_commentDestructiveTHE MODERATION TOOL for TikTok ads, and the TikTok twin of moderate_meta_comment. Hiding takes a comment out of public view — everyone stops seeing it except the person who wrot...
-
react_to_bluesky_dmDestructiveAdd or remove an emoji reaction on one message in a Bluesky DM \u2014 the light acknowledgement that does not need a written reply, and the thing to reach for when someone says ...
-
remove_applovin_ads_creative_setDestructiveTake an AppLovin creative set out of its campaigns (all of them, or campaignIds). AppLovin’s API has no delete or archive, so this is its only removal: the set and its assets st...
-
remove_bing_webmaster_siteDestructiveRemove a site from the connected Bing Webmaster account — the heaviest thing in this connector. GATED ON BLAST RADIUS: called WITHOUT
-
remove_bing_webmaster_sitemapDestructiveRemove a sitemap from Bing. GATED ON BLAST RADIUS, not just on intent: called WITHOUT
-
remove_memberDestructiveRemove a member from this profile by email — they lose access (you can re-invite them later), AND every connection THEY made on this profile is disconnected with them: their own...
-
remove_openai_ads_daily_spend_limitDestructiveRemove the account-wide DAILY spending limit on ChatGPT Ads. This takes a spending CEILING off the whole account, so campaigns may then spend up to their own budgets every day; ...
-
reply_to_google_business_reviewDestructiveAnswer a customer review publicly, as the business, on the brand’s Google Business Profile listing — or delete a reply that is already there. THIS IS AN UPSERT: a listing has ex...
-
set_tiktok_ads_brand_safetyDestructiveSet what content this TikTok ad account’s ads may appear next to. THREE RULES TIKTOK IMPOSES AND ONE THING THAT CANNOT BE UNDONE. (1) The suitability controls move as a TRIO: Ti...
-
unlink_google_ads_from_analyticsDestructiveREMOVE the link between a GA4 property and a Google Ads account. The link itself is trivially re-creatable, which is why this is not a one-way-door gate — but what breaks downst...
-
unsubscribe_meta_webhooksDestructiveRemove this app’s webhook subscription from a Page, so Meta stops pushing its events. It removes the WHOLE subscription — Meta’s DELETE takes no field list — so it is all fields...
-
update_youtube_channelDestructiveAPPLY THE BRAND TO THE CHANNEL ITSELF — banner art, description, keywords, country and the trailer non-subscribers see. Every other YouTube tool brands the videos; this brands t...
-
buy_creditsFinancialOut of credits? Top up with a credit PACK. Call with no argument to list the available packs (id · credits · price). If the account has a saved card and you have billing-admin r...
-
refund_stripe_chargeFinancialRefund a Stripe charge (ch_… or a pi_… payment intent): the full refundable amount, or a partial
-
set_auto_reloadFinancialTurn automatic credit reloads on or off (admin only): when the balance drops below a threshold, the card on file is charged for a top-up pack — SERVER-SIDE, even with no app ope...
-
set_google_ads_budgetFinancialCreate a new daily budget, or change an existing budget’s daily amount (pass budgetResourceName). Raising the budget on a LIVE (ENABLED) campaign increases real spend immediatel...
-
set_meta_campaign_statusFinancialTurn a campaign ON (ACTIVE) or OFF (PAUSED). ACTIVATING STARTS REAL AD SPEND — you MUST first show the user the campaign name + its daily budget, get an explicit yes, then call ...
-
upgrade_planFinancialChange this account
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.