Critical-risk tools in AWS MCP Server
14 of the 54 tools in AWS MCP Server are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
delete-amiDestructiveDelete an AMI
-
delete-bucketDestructiveDelete an S3 bucket in the given region
-
delete-db-instanceDestructiveDelete a given RDS DB instance in the given region
-
delete-instance-tagDestructiveDelete instance tag
-
delete-internet-gatewayDestructiveDelete an internet gateway by ID in the given region
-
delete-key-pairDestructiveDelete a key pair in the given region
-
delete-route-tableDestructiveDelete a route table in the given region
-
delete-security-groupDestructiveDelete a security group in the given region
-
delete-subnetDestructiveDelete a subnet by subnet ID in the given region
-
delete-vpcDestructiveDelete a VPC by VPC ID in the given region
-
revoke-security-group-egressDestructiveRevoke a security group egress in the given region
-
revoke-security-group-ingressDestructiveRevoke a security group ingress in the given region
-
detach-internet-gatewayDestructiveDetach an internet gateway from a VPC
-
terminate-ec2-instanceDestructiveTerminate an EC2 instance in a given region
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.