Critical-risk tools in Nitrostack
42 of the 697 tools in Nitrostack are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
cancel_appointmentDestructivecancel_appointment
-
cancel_followupDestructivecancel_followup
-
cancel_orderDestructiveCancel a flight order and request refund if applicable
-
clean_temp_filesDestructiveDeletes files in the user and Windows temp folders to free disk space. Files currently in use are skipped automatically. Requires confirm:true — call once first to preview.. CRI...
-
clear_icon_cacheDestructiveClears the Windows icon cache and rebuilds it on next Explorer restart. Fixes generic/blank/wrong desktop and taskbar icons — a well-known trick among power users but almost unh...
-
commit_transactionDestructiveClose the transaction boundary. Committed transactions cannot be reversed. Call this when all steps succeeded and you want to discard the compensation data.
-
delete_accountDestructiveDelete a CRM account. No compensator — this is the inverse of create_account.
-
delete_chat_sessionDestructiveDelete a chat session
-
delete_documentDestructiveDelete a document, removing its chunks, vectors, and graph relationships
-
delete_messageDestructiveDelete a message, leaving a visible tombstone. This is the inverse of post_message.
-
delete_projectDestructiveDelete a project
-
empty_recycle_binDestructiveEmpties the Windows Recycle Bin. Requires confirm:true — call once first to preview.. CRITICAL: Never output
-
obsidian-delete-noteDestructiveDelete a note from your local Obsidian Vault.
-
release_environmentDestructiveStop and destroy an environment owned by the authenticated agent before its TTL. Repeating release on an already released environment has no additional effect.
-
remove_policy_ruleDestructiveRevoke an agent\
-
reset_demoDestructiveReset all mock servers to their original, clean state after running attack simulations.
-
reset_demo_dataDestructivereset_demo_data
-
revoke_api_keyDestructiveRevoke an API key. No compensator — this is the inverse of grant_api_key.
-
revoke_inviteDestructiveRevoke a pending invite. No compensator — this is the inverse of invite_user.
-
rollback_transactionDestructiveCompensate every reversible step of a transaction in strict reverse order. Irreversible steps are skipped and reported for manual handling. Returns a per-step report. A PARTIAL ...
-
screen_fraudDestructiveFraud, velocity and AML/PEP watchlist screening (mock). Returns CLEAR / REVIEW / BLOCK with signals and a score. A REVIEW verdict should pause for human handoff.
-
send_emailDestructiveSend an email. Cannot be undone — only counteracted by a retraction email within a short window.
-
analyze_recurring_and_purchase_impactFinancialUnified Insights Engine — Scan for recurring charges/subscriptions (mode: recurring_charges) or simulate the financial & goal-delay impact of a hypothetical purchase (mode: purc...
-
authorize_paymentFinancialPlace a payment authorization hold. Decays to a mere counteraction option after 7 days.
-
capture_paymentFinancialCapture a payment charge. Cannot be undone — only counteracted by a manual refund.
-
create_payment_linkFinancialGenerate WhatsApp and UPI payment links to request a specific amount from a person.
-
estimate_capital_gainsFinancialCapital Gains Estimator — before selling/redeeming a mutual fund, estimates the capital-gains tax you\
-
estimate_downtime_costFinancialCalculate financial impact projection for machine downtime based on lost throughput revenue, idle labor, expedited maintenance rates, and delivery penalties.
-
extract_and_split_receiptFinancialExtract line items from a receipt image, assign them to people using an assignment prompt, and automatically split the bill to create real debt records.
-
generate_offersFinancialProduce up to 3 priced offers (amount, ROI, EMI, APR, total cost) with a recommended flag. Intent-aware: FAST_TRACK (medical/emergency) surfaces the lowest-EMI offer first. Only...
-
ingest_and_manage_transactionsFinancialMaster Ingestion & Cashflow Engine — Ingest financial transactions via CSV statement upload (action: csv_upload), manual entry (action: manual_entry), set monthly income (action...
-
issue_payoutFinancialIssue a payout to an external recipient. Irreversible once it leaves the platform.
-
manage_group_expensesFinancialUnified Group Expenses Management — Log shared expenses with Splitwise debt simplification (action: split_expense), add group participants (action: add_participant), or check ne...
-
manage_investment_and_sipFinancialUnified Investment & SIP Engine — Calculate SIP returns, generate risk-customized SIP investment plans, or recommend fund asset categories based on budget and horizon.
-
manage_savings_and_emergency_fundFinancialSavings & Emergency Reserve Engine — Identify discretionary spend trimming opportunities (action: suggest_savings) or calculate and manage 3-to-6 month emergency reserve safety ...
-
minimize_group_settlementFinancialCompress a complex web of multi-friend group debts into the minimal number of direct settlements with payment links.
-
plan_my_financesFinancialOne-shot personal finance & tax plan. Given your income (and optionally a mutual fund holding and
-
reallocate_capitalFinancialShifts budget between department ledgers. HIGH RISK — queued for human approval. Check the source department floor before proposing.
-
refund_paymentFinancialRefund a captured payment. This is the inverse of capture_payment.
-
split_billFinancialSplit a bill among multiple people proportionally, factoring in tax and tip.
-
suggest_investmentsFinancialSuggest investments for a given amount of spare cash.
-
transfer_stockFinancialtransfer_stock
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.