Critical-risk tools in Agentview
10 of the 55 tools in Agentview are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
claim_displayDestructiveConverts an unclaimed guest or pending display into a managed personal display owned by the authenticated user. This permanently transfers ownership and counts against the user'...
-
clear_displayDestructiveRemoves the current live content from a display and returns it to its idle/default state. Viewers will immediately see the change. Use this when the user wants to blank or reset...
-
delete_assetDestructiveDeletes one or more assets. Displays referencing deleted assets will show broken images. Requires authentication with at least content_only scope.
-
delete_displayDestructivePermanently deletes a display and all its associated content. This action cannot be undone. Use this only when the user explicitly confirms they want to remove the display. Requ...
-
delete_organizationDestructivePermanently deletes an organization, releasing all its displays and removing all members. Only the owner can delete. This cannot be undone. Requires admin scope.
-
logoutDestructiveClears the cached authentication identity from the current MCP session. Use this when the user wants to end the session or switch accounts. This does not revoke the underlying J...
-
remove_display_from_orgDestructiveRemoves a display from an organization, clearing its group assignment and all display grants. The display becomes unassigned. Requires admin scope and admin or owner role.
-
remove_display_grantDestructiveRemoves a user's access grant from a display within an organization. Requires admin scope and admin or owner role.
-
remove_memberDestructiveRemoves a member from an organization. Transfers their owned displays to a successor, unassigns their license allocations, and removes their display grants. Cannot remove the la...
-
revoke_api_keyDestructivePermanently revokes an API key. This is irreversible — the key will immediately stop working. Requires admin scope.
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.