Critical-risk tools in Meridian
47 of the 235 tools in Meridian are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
accept_handoffDestructive[SUPPORT] Read-only: (1bd5e810) Canonical receiver-side acceptance check for a handoff envelope — composes token verification, capability/tool availability, tool-manifest drift,...
-
acquire_docx_document_leaseDestructive[MAINTENANCE] 6507e83a — Whole-document cross-process lease for .docx files, the counterpart claim_docx_region never provided (that tool hard-requires a specific element_id). Us...
-
answer_hitlDestructive[SUPPORT] Answer a pending HITL request programmatically. Marks it answered so the waiting session can resume. Use list_hitl_requests to find request IDs. Persistent-state discl...
-
batch_mutateDestructive[SUPPORT] 133bfff6 — run a batch of TRANSACTIONAL mutation entries in ONE call, mixing entry kinds selected per-entry via 'kind': 'sprint_item_pointer' (attach a pointer — same ...
-
capture_research_findingDestructive[SUPPORT] Inline capture for web/paper research during planning: save a finding from a URL as an addressable note with the source link, optionally linked to a decision. A resear...
-
checkpointDestructive[SUPPORT] Save progress mid-session. Runs auto_capture (buckets done tasks into a note), generates a delta handoff, and returns a compact summary with what was done, what's pend...
-
claim_docx_regionDestructive[MAINTENANCE] f7ee1ba7 — Model B scoped-region claiming for .docx files. Claim a specific paragraph/element by its durable `element_id` (the w14:paraId surfaced by get_document_...
-
claim_fileDestructive[SUPPORT] Claim edit rights on a file for this session. Whole-file by default (auto-expires after 2 hours). For symbol-level claims — so two sessions can edit the same file if t...
-
claim_sprint_itemDestructiveClaim a pending sprint item: sets status to in_progress and records claimed_at + actor. Read-only: false. Rejects if the item is already in_progress, done, failed, skipped, its ...
-
clear_capability_profileDestructive[SUPPORT] 02038afe — Delete a scope's ENTIRE capability profile row (both its capabilities and its disabled_capability_ids) so it reverts to purely inheriting from less specific...
-
clone_profile_layerDestructive[SUPPORT] 0bec79a7 (PROFILE-5) — Copy one layer's fields/reset_fields/provenance onto another scope, going through the exact same validation/hashing path as save_profile_layer (...
-
delete_custom_hookDestructive[MAINTENANCE] 273287cb — delete a user-defined hook by id (the id returned by add_custom_hook / get_custom_hooks). Idempotent: deleting an already-gone hook returns {deleted:fal...
-
delete_noteDestructive[MAINTENANCE] Hard-delete a project note by id. Persistent-state disclosure: on hosted Meridian, supplied text and project/session metadata -- including task log entries, pinned...
-
delete_sprint_item_pointerDestructive[MAINTENANCE] 2976e168 — delete ONE generic pointer from a sprint item by its pointer id (the id returned by add_sprint_item_pointer / get_sprint_item_pointers). Idempotent: ret...
-
delete_watchlist_queryDestructive[SUPPORT] Delete a saved research watchlist query. Scoped to project_id + the watchlist tag, so it never deletes an unrelated note. Persistent-state disclosure: on hosted Meridi...
-
dismiss_hitlDestructive[SUPPORT] Dismiss a HITL request (won't-answer / no longer relevant). Stays in audit trail. Use list_hitl_requests to find request IDs. Persistent-state disclosure: on hosted Me...
-
fan_out_sprint_itemsDestructive[SUPPORT] Bulk-insert sprint items from a single orchestrator call — decompose a goal into parallel work items without N sequential add_sprint_item calls. Pass a list of {title,...
-
idle_until_all_doneDestructive[MAINTENANCE] PARALLEL COORDINATION (d3a3a01d): non-blocking barrier check across sibling sessions. Returns {all_done, pending, statuses}; a session is done when closed/archived...
-
index_equationDestructive[MAINTENANCE] 06df6ab3 — index ONE Word equation (OMML) against a document already stored in the doc-structure store — populated by ingest_document (which registers a docx/latex...
-
index_figureDestructive[MAINTENANCE] c623e648 — index ONE figure into the SEMANTIC figure index against a document already stored in the doc-structure store — populated by ingest_document (which regis...
-
index_tableDestructive[MAINTENANCE] 2622182d — index ONE table into the SEMANTIC table index against a document already stored in the doc-structure store — populated by ingest_document (which registe...
-
ingest_documentDestructive[SUPPORT] Turn a Word/PDF/text document into a queryable kind='document' note with a source link — a report, thesis chapter, or spec doc becomes searchable project memory. Pass ...
-
ingest_document_structureDestructive[MAINTENANCE] db42acce — persist pre-parsed structural data (headings/figures/tables) into the doc-structure store, keyed on the SAME source as ingest_document(content=...) so f...
-
link_figure_captionDestructive[MAINTENANCE] 0ff8b982 — DURABLY link an already-indexed figure (doc_figures row) to its caption paragraph (a doc_elements id), by stable structural id rather than paragraph pro...
-
link_flag_to_sectionDestructive[MAINTENANCE] 8ca89e8f — DURABLY link a docx section/paragraph/figure/table (any doc_elements id — the same id space index_figure/index_table/link_figure_caption already anchor ...
-
link_proposal_lineageDestructive[SUPPORT] Record a typed lineage relation between two EXISTING proposals: from_proposal_id --relation_type--> to_proposal_id (to_proposal_id is the older/predecessor side). Idem...
-
link_table_captionDestructive[MAINTENANCE] 42d398a5 — DURABLY link an already-indexed table (doc_tables row) to its caption paragraph (a doc_elements id), by stable structural id rather than paragraph proxi...
-
log_taskDestructive[SUPPORT] Log a task this session completed or is working on. Valid statuses: pending, in_progress, done, failed, backlog, future, backburner. Persistent-state disclosure: on ho...
-
purge_ai_logDestructive[MAINTENANCE] c0168425 — Project-scoped, cutoff-based retention sweep spanning BOTH ai_log_events (meridian.db.ai_log.purge_events_before) and their stored artifacts (meridian.a...
-
receive_messagesDestructive[MAINTENANCE] PARALLEL COORDINATION (d3a3a01d): fetch unread messages addressed to a session (oldest first) and mark them read by default. The receive side of send_message. Pers...
-
reconcile_stale_claimsDestructive[MAINTENANCE] 56e9b3c7 — project/version-scoped, auditable stale-claim reconciliation sweep. The bulk counterpart to claim_sprint_item's own inline autonomous reconciliation (wh...
-
record_experiment_eventDestructive[SUPPORT] 3f6b8715 — manually record an experiment_events row (dead_end|pivot|breakthrough|note|milestone). Separate from, and coexists freely alongside, the auto-skeleton event...
-
record_handoff_correctionDestructive[MAINTENANCE] 3af86d28 — record a corrective handoff when a blocked executor session reaches a wall after receiving a handoff (its evidence/scope no longer holds, a pointer stop...
-
refresh_contextDestructive[SUPPORT] Single-call post-compaction recovery for planning chats. Returns a COMPACT snapshot — current sprint + progress, next pending items, the active session id, recent hand...
-
release_docx_document_leaseDestructive[MAINTENANCE] 6507e83a — Release a session's whole-document lease on a .docx file, if held. Returns {released: <0 or 1>, session_id, file_path}. Persistent-state disclosure: on ...
-
release_docx_region_claimsDestructive[MAINTENANCE] f7ee1ba7 — Release scoped docx-region claims held by a session. Without element_id releases all claims on the file; with element_id releases only that one element....
-
release_fileDestructive[SUPPORT] Release a file lock (and any symbol claims this session holds on it). Persistent-state disclosure: on hosted Meridian, supplied text and project/session metadata -- in...
-
release_sprint_item_claimDestructive[MAINTENANCE] W1-I — voluntarily release a LIVE in_progress claim on a sprint item back to pending. Distinct from reconcile_stale_claims: that tool is for a claim whose owning s...
-
relocate_sprint_item_pointerDestructive[SUPPORT] W1-J — atomically UPDATE an existing generic pointer's targets/source_type/label IN PLACE (a single UPDATE statement), replacing the delete_sprint_item_pointer + add_s...
-
reopen_proposal_gateDestructive[SUPPORT] Invalidate a still-standing proposal gate decision (e.g. new evidence surfaced) so resolve_proposal_gate can be called again. Resets the lane to 'blocked' (fail-safe),...
-
request_hitlDestructiveSurface a question to the human-in-the-loop queue. ALWAYS use this to ask the human a question — never just ask in chat, which is invisible to the dashboard and to an unattended...
-
reset_plugin_overrideDestructive[MAINTENANCE] Clear a tenant's stored command/config override for one plugin slot, resetting it back to the built-in default. Fixes the gap where stale_override detection (surfa...
-
reset_profile_layerDestructive[SUPPORT] 0bec79a7 (PROFILE-5) — Delete a scope's ENTIRE profile-layer row so it reverts to purely inheriting from less-specific layers — mirrors clear_capability_profile's sema...
-
split_sprint_itemDestructive[SUPPORT] Split a sprint item into multiple smaller items. The original is closed (skipped) and N new items are created with split_from referencing the original. Returns list of...
-
store_findingDestructive[MAINTENANCE] PARALLEL COORDINATION (c35370cc): persist a per-task intermediate result to the session_findings table so it survives session boundaries. Parallel reader agents wr...
-
finalize_wave_runFinancial[SUPPORT] 2a654cb0 — IDEMPOTENT FINALIZATION: close a wave run opened by start_wave_run. Safe to retry: if the run is already merged this returns the ORIGINAL result with alread...
-
transfer_sprint_item_claimFinancial[MAINTENANCE] W1-I — hand a LIVE in_progress claim on a sprint item off to a different actor/session directly, without a reset-to-pending-then-reclaim cycle. The item's status n...
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.