Critical-risk tools in Q402 Mcp
18 of the 41 tools in Q402 Mcp are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
q402_clear_delegationDestructiveClear the EIP-7702 delegation on a Q402 chain for the configured wallet.
-
q402_redstone_trigger_cancelDestructivePermanently cancel a RedStone trigger so it never fires again.
-
q402_bridge_sendFinancialExecute a Chainlink CCIP USDC bridge across the 3-chain triangle (eth/avax/arbitrum) on
-
q402_escrow_createFinancialCreate a Q402 Gasless Escrow (non-custodial, EIP-7702). Publishes a
-
q402_escrow_disputeFinancialA party (buyer or seller) disputes an open escrow (requires the escrow named an arbiter, before the release deadline). The arbiter then resolves off-tool. Confirm with the user ...
-
q402_escrow_lockFinancialFund a pending escrow: the BUYER gaslessly locks the amount into the vault via EIP-7702 (Q402 relays + sponsors gas). MOVES REAL FUNDS.
-
q402_escrow_refundFinancialPermissionlessly refund a locked escrow to the BUYER - only valid AFTER the release deadline (or, if disputed, after the arbiter resolve window). Confirm with the user first (co...
-
q402_escrow_releaseFinancialBUYER releases a locked escrow to the SELLER (buyer-signed, gasless). MOVES REAL FUNDS irreversibly. Confirm with the user first (confirm:true).
-
q402_oft_sendFinancialBridge USDT (USDT0) across chains (eth/arbitrum/mantle/monad/xlayer) via LayerZero OFT, from the Agent
-
q402_payFinancialUSE THIS TOOL whenever the user asks to send, transfer, or pay USDC / USDT /
-
q402_recurring_cancelFinancialCancel an active recurring-payment rule on the Agent Wallet. Takes a
-
q402_recurring_resumeFinancialResume a paused or stopped recurring-payment rule. Takes a ruleId
-
q402_redstone_trigger_createFinancialArm a gasless payout that fires when a RedStone feed (NAV / price / RWA)
-
q402_request_payFinancialPay a Q402 payment request from your own Agent Wallet, gaslessly. Give it a req_ id (from a
-
q402_stakeFinancialWRITE - MOVES FUNDS. Stakes the Agent Wallet
-
q402_unstakeFinancialWRITE - MOVES FUNDS. Unstakes the Agent Wallet
-
q402_yield_depositFinancialWRITE - MOVES FUNDS. Supplies the Agent Wallet
-
q402_yield_withdrawFinancialWRITE - MOVES FUNDS. Withdraws the Agent Wallet
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.