Critical-risk tools in Ncp
13 of the 275 tools in Ncp are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
backupDestructiveBackup mysql-api database
-
bulk_deleteDestructiveBulk delete documents
-
deleteDestructiveDelete scheduled job.
-
delete_eventDestructiveDelete calendar event
-
delete_keyDestructiveDelete Redis key
-
delete_memoryDestructiveDelete a memory entry
-
purge_cacheDestructivePurge Cloudflare cache
-
removeDestructiveRemove an MCP server from NCP configuration. First use
-
remove_containerDestructiveRemove a Docker container
-
write_queryDestructiveExecute an INSERT, UPDATE, or DELETE query
-
create_chargeFinancialProcess a payment charge using Stripe
-
create_refundFinancialProcess a refund for a Stripe charge
-
create_subscriptionFinancialCreate a recurring subscription
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.