Critical-risk tools in Jshookmcp
29 of the 736 tools in Jshookmcp are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
adb_uninstallDestructiveUninstall a package from a device, optionally keeping app data.
-
cleanup_artifactsDestructiveClean generated artifacts by age and size.
-
clear_all_cachesDestructiveClear all internal caches. Destructive — prefer smart_cache_cleanup.
-
clear_collected_dataDestructiveClear collected script data, caches, and in-memory indexes.
-
dart_destroy_sessionDestructiveDestroy a Dart snapshot session created by dart_create_session, releasing the cached parsed snapshot. Returns destroyed=true if the session existed, false if it was unknown or a...
-
exploit_cache_clearDestructiveClear all cached exploit-dev results. Use when binaries have been modified or to free memory.
-
exploit_cache_invalidateDestructiveInvalidate cached exploit-dev results for a specific binary (by path). Computes the binary hash and removes all matching cache entries. Call without binaryPath to clear the enti...
-
extension_uninstallDestructiveUninstall an extension from the local registry.
-
ghidra_decompileDestructiveDecompile a function using Ghidra.
-
ida_decompileDestructiveDecompile a function using IDA Pro.
-
jadx_decompile_apkDestructiveHigh-level JADX APK decompile: decompile the whole APK to a stable output directory and return sourcesDir for jadx_search_code.
-
manual_token_cleanupDestructiveClear stale entries and reset counters to free 10-30% of token budget.
-
memory_antidetectionDestructiveAnti-detection hardening toolkit. Actions: check (run all detectors — kernel callbacks, instrumentation callback, AMSI/ETW status, chaos mode, platform info), harden (apply AMSI...
-
memory_batch_editDestructiveWrite a value to ALL addresses in a scan session at once. Thin wrapper that iterates through the session address list and calls writeValue for each. Capped at 1000 addresses per...
-
memory_scan_sessionDestructiveManage scan sessions. Actions: list (all sessions), delete (by sessionId), export (as JSON).
-
memory_unregister_typeDestructiveRemove a registered custom scan type by name.
-
nemu_destroy_sessionDestructiveDestroy an emulator session and free its memory (mapped library, stack, JNI tables).
-
page_cookiesDestructiveManage page cookies; clear requires matching expectedCount.
-
page_local_storageDestructiveRead, write, delete, or clear localStorage entries for the current origin.
-
page_session_storageDestructiveRead, write, delete, or clear sessionStorage entries for the current origin.
-
proxy_clear_logsDestructiveClear all captured proxy request/response logs.
-
proxy_clear_rulesDestructiveClear active proxy interception rules while keeping the proxy running.
-
proxy_remove_ruleDestructiveRemove a single proxy interception rule by endpointId. Returns the removed rule record.
-
reset_token_budgetDestructiveHard-reset all token budget counters. Destructive — prefer manual_token_cleanup.
-
session_progress_clearDestructiveClear session progress entries. With no
-
snapshot_restoreDestructiveRestore a directory to a recorded shadow-git snapshot. DESTRUCTIVE: files modified after the snapshot are overwritten, files created after it are DELETED, and files deleted afte...
-
tls_keylog_sealDestructiveEncrypt the current keylog file in place with a fresh ephemeral key and securely wipe the plaintext source. Mitigates disk-forensics exposure (pagefile/hibernation/TEMP scraping...
-
v8_heap_snapshot_deleteDestructiveDelete persisted V8 heap snapshot artifact files (.heapsnapshot data + .meta.json sidecar) and drop the matching in-memory cache entry. Use deleteAll=true to remove every persis...
-
webhookDestructiveManage webhook endpoints for external callbacks. Actions: create, list, delete, commands.
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.