Critical-risk tools in instantKOM MCP Server
41 of the 245 tools in instantKOM MCP Server are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
bulk_delete_custom_fieldsDestructiveDelete multiple custom field definitions at once (max 100)
-
delete_accountDestructiveDelete the current user account (irreversible)
-
delete_api_keyDestructiveDelete an API key by ID
-
delete_botDestructiveDelete a bot by ID
-
delete_bot_env_varDestructiveDelete a bot environment variable
-
delete_bot_env_var_valueDestructiveDelete a recipient-specific environment variable value
-
delete_bot_filterDestructiveDelete a bot filter
-
delete_broadcastDestructiveDelete a newsletter by ID
-
delete_broadcast_mediaDestructiveDelete newsletter media
-
delete_chatDestructiveDelete a chat by ID
-
delete_contactDestructiveDelete a contact by ID
-
delete_contact_custom_field_valueDestructiveRemove the value of a custom field for a specific contact
-
delete_custom_fieldDestructiveDelete a custom field definition and all its values across all contacts
-
delete_exportDestructiveDelete an export
-
delete_feedDestructiveDelete a feed by ID
-
delete_flowDestructiveDelete a flow and all its nodes and edges. Referenced bots are not deleted.
-
delete_flow_edgeDestructiveRemove a connection between nodes in a flow
-
delete_flow_nodeDestructiveRemove a node from a flow. Also removes connected edges. The bot is not deleted.
-
delete_messageDestructiveDelete a message
-
delete_message_mediaDestructiveDelete message media
-
delete_object_folderDestructiveDelete a folder
-
delete_pollDestructiveDelete a poll by ID
-
delete_poll_optionDestructiveDelete a poll option
-
delete_qr_codeDestructiveDelete a QR code by ID
-
delete_segmentationDestructiveDelete a segmentation by ID
-
delete_short_linkDestructiveDelete a short link by ID
-
delete_super_widgetDestructiveDelete a SuperWidget by ID
-
delete_tagDestructiveDelete a tag by ID
-
delete_team_member_by_idDestructiveDelete a team member by ID via Public API
-
delete_templateDestructiveDelete a template by ID
-
delete_ticketDestructiveDelete a ticket by ID
-
delete_ticket_messageDestructiveDelete a ticket message
-
delete_widgetDestructiveDelete a widget
-
remove_dashboard_widgetDestructiveRemove a widget from the dashboard. Some widgets may be non-removable.
-
remove_ip_from_whitelistDestructiveRemove an IP address from the whitelist
-
remove_segmentation_tagDestructiveRemove a tag from a segmentation
-
remove_team_memberDestructiveRemove a team member
-
unsubscribe_webhookDestructiveDelete a webhook subscription by ID
-
apply_couponFinancialApply a coupon code to the account
-
subscribe_to_planFinancialSubscribe to a plan
-
update_payment_methodFinancialUpdate payment method
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.