Critical-risk tools in 1ly
7 of the 24 tools in 1ly are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
1ly_delete_linkDestructiveDelete an API link by id (requires ONELY_API_KEY).
-
1ly_revoke_keyDestructiveRevoke an API key for the authenticated agent store (requires ONELY_API_KEY).
-
1ly_callFinancialCall a paid API on 1ly.store with automatic x402 payment. Returns the API response and purchase metadata for leaving a review.
-
1ly_claim_feesFinancialClaim Bags fee share for a token (Bags only).
-
1ly_launch_tokenFinancialLaunch a token on Bags.fm (v2 flow). Handles metadata, fee config, launch tx, signing, and submission.
-
1ly_trade_tokenFinancialTrade tokens on Bags (Bags only).
-
1ly_withdrawFinancialRequest a withdrawal of your available balance to a Solana wallet (requires ONELY_API_KEY).
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.