Critical-risk tools in Apps Script MCP
7 of the 60 tools in Apps Script MCP are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
delete_deployment_toolDestructiveDelete a deployment.
-
delete_drive_file_toolDestructivePermanently delete a file from Google Drive.
-
delete_event_toolDestructiveDelete a calendar event.
-
delete_script_project_toolDestructiveDelete an Apps Script project.
-
delete_task_toolDestructiveDelete a task from Google Tasks.
-
remove_drive_permission_toolDestructiveRemove a permission from a file or folder.
-
trash_drive_file_toolDestructiveMove a file to trash in Google Drive (recoverable).
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.