Critical-risk tools in OpenChrome
4 of the 106 tools in OpenChrome are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
cookiesDestructiveManage browser cookies (get, set, delete, clear).
-
crawl_cancelDestructiveMark a crawl job as cancelled. Returns immediately. Subsequent
-
element_pickDestructiveStart or cancel an in-page human element picker overlay. Returns selector, DOM, style, and bounding-box facts; it does not persist skills directly.
-
oc_checkpointDestructiveSave, load, list, or delete automation checkpoints for long-running session continuity.
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.