Critical-risk tools in Photopea
2 of the 34 tools in Photopea are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
photopea_clear_selectionDestructive 4/5Deselect the current selection in the active document, removing the marching ants. Does not modify any pixel data. Use after fill_selection or other selection-based operations a...
-
photopea_delete_layerDestructive 4/5Permanently remove a layer from the active document by name or index. The next layer in the stack becomes active after deletion. Use get_layers to see available layers before de...
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.
More on Photopea
Enforce policy on Photopea
One command generates a policy scaffold for every server in your MCP config.
npx -y @policylayer/intercept init