Critical-risk tools in Mcp Anything
21 of the 261 tools in Mcp Anything are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
cli_uninstallDestructiveUninstall a CLI-Anything harness.
-
component_removeDestructivecomponent_remove
-
cookie_clearDestructiveClear all cookies from the current browser session.
-
cookie_deleteDestructiveDelete a cookie by name.
-
doc_paragraph_removeDestructiveRemove a paragraph/element by index from the active Writer document.
-
doc_remove_elementDestructiveRemove an element from the document.
-
filter_removeDestructivefilter_remove
-
layer_removeDestructiveRemove a layer by index.
-
network_clear_logDestructiveClear the network request log.
-
network_remove_interceptorDestructiveRemove a network request interceptor by pattern.
-
node_removeDestructivenode_remove
-
object_removeDestructiveRemove an object from the scene by index.
-
pres_slide_removeDestructiveRemove a slide from the active Impress presentation.
-
scene_removeDestructiveRemove a scene from the project.
-
script_removeDestructiveRemove a script from the project.
-
selection_noneDestructiveDeselect all (remove active selection).
-
session_resetDestructiveReset the browser session to a clean state (about:blank, no cookies or storage).
-
sheet_deleteDestructiveDelete a sheet from the active Calc spreadsheet. Cannot delete the last sheet.
-
source_removeDestructivesource_remove
-
storage_clear_localDestructiveClear all localStorage data.
-
storage_remove_localDestructiveRemove a key from localStorage.
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.