Critical-risk tools in Lovie Company Formation MCP
27 of the 340 tools in Lovie Company Formation MCP are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
accounting_cancel_scheduleDestructiveCancel an accrual schedule so no further periodic entries are generated. Entries already posted for elapsed periods are kept. Audit-logged.
-
accounting_confirm_statement_matchDestructiveRecord that a ledger transaction settles a bank-statement line, or clear an existing match by omitting the transaction. Refused once the statement is closed.
-
accounting_delete_journal_entryDestructiveDelete or void a journal entry. For entries tied to a transaction prefer re-categorizing the transaction (the entry re-derives). Deleting a derived entry is temporary — the engi...
-
cap_table_clear_cap_table_stakeholdersDestructiveClearCapTableStakeholders deletes every stakeholder of a company in a single DB-level operation. Used by the "replace cap table" import flow.
-
cap_table_close_cap_table_roundDestructiveCloseCapTableRound PERMANENTLY closes the round: runs the calc engine, persists the SAFE conversions + ownership snapshots, and flips the round to CLOSED. This is the action for...
-
cap_table_delete_cap_table_agreementDestructiveDeleteCapTableAgreement removes an agreement.
-
cap_table_delete_cap_table_roundDestructiveDeleteCapTableRound permanently removes an unpriced SAFE round (open or light-closed) plus its round-scoped securities/agreements/snapshots. Priced / engine-closed rounds are re...
-
cap_table_delete_cap_table_securityDestructiveDeleteCapTableSecurity removes one holding.
-
cap_table_delete_cap_table_stakeholderDestructiveDeleteCapTableStakeholder removes one stakeholder from a cap table.
-
cap_table_set_cap_table_pipeline_statusDestructiveMoves ONE investor's holding along the fundraising pipeline. Use this to change a stage — never UpdateCapTableSecurity, which is a full replace and will blank any field you do n...
-
documents_delete_saved_signatureDestructiveDeleteSavedSignature removes one of the caller's saved signatures. Exposed because ListSavedSignatures already is: the agent could name a founder's signatures without being able...
-
formation_delete_pending_domainDestructiveRemoves an abandoned pending domain purchase attempt from the company's domain list. Only pending (never-completed) purchases can be removed; registered domains cannot be delete...
-
formation_remove_shareholderDestructiveRemoves one owner from a formation and reports how many remain and what ownership now totals. The freed percentage is NOT given to anyone else, so the total will usually stop re...
-
signature_void_envelopeDestructiveVoidSignatureEnvelope voids an envelope (owner-gated, ownership checked like SignAsCompany): writes a terminal DOCUMENT_VOIDED status + voided_at and appends a hash-chained docu...
-
trademark_delete_applicationDestructiveDeleteApplication erases an application the applicant has abandoned, along with its classes, documents, and clearance reports. Refused once the package has gone to the firm: fro...
-
vendor_bill_cancel_vendor_billDestructiveCancel an open vendor bill so it no longer counts as an open payable. Only OPEN bills can be cancelled; a bill already paid or cancelled cannot.
-
accounting_confirm_transfer_pairFinancialConfirm that two journal entries are the two halves of one transfer. The entry named first is reposted from funding account to funding account; the counterpart's transaction is ...
-
accounting_suggest_transfer_pairsFinancialRank the journal entries that could be the other half of a transfer between the company's own accounts: opposite direction, same amount, different instrument, dated within a few...
-
accounting_unpair_transferFinancialUndo a confirmation: the mirror returns and both halves are re-derived.
-
autonomous_payFinancialSubmit a signed payment mandate for autonomous execution. Runs the four-check pipeline and the per-agent autonomy fence; payments outside the agent's envelope are gated to human...
-
banking_confirm_initial_transferFinancialRecords the opening deposit a founder chose for their banking application. This stores an intention only — it does not move money, and no funds are transferred by any part of Lo...
-
cap_table_record_cap_table_refundFinancialRecordCapTableRefund records a refund into the money-movement ledger (refund, confirmed) and flips the security's pipeline_status to 'refunded'.
-
commit_transferFinancialExecute a sealed draft. Moves money. Call ONLY after approval_session_get_approval_session_status returned APPROVED for the approval_session_id: a commit sent while the approval...
-
formation_create_domain_transfer_checkoutFinancialStarts transferring a domain the company already owns elsewhere INTO Lovie: returns a Stripe Checkout URL covering the transfer (which includes a one-year renewal). After paymen...
-
formation_start_domain_transferFinancialBegins the paid transfer at the registrar using the EPP/auth code the user obtained from their current provider. The code is used once and never stored. Transfers take days; tra...
-
mcp_draft_transferFinancialSeal a transfer to a registered recipient as a server-held draft and get back a summary plus a single-use draft_id. Moves no money. Requires an active trusted device. Any change...
-
request_transfer_approvalFinancialSend the trusted-device approval for a sealed draft to the user's phone and return its approval_session_id. Tell the user to answer on their phone within ~5 minutes. Do NOT call...
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.