Critical-risk tools in Linode MCP Server
57 of the 416 tools in Linode MCP Server are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
cancel_accountDestructiveCancel your account
-
cancel_backupsDestructiveCancel backups for a Linode instance
-
cancel_object_storageDestructiveCancel Object Storage service
-
delete_alert_definitionDestructiveDelete an alert definition
-
delete_api_tokenDestructiveDelete an API token
-
delete_config_interfaceDestructiveDelete an interface from a configuration profile
-
delete_domainDestructiveDelete a domain
-
delete_domain_recordDestructiveDelete a domain record
-
delete_firewallDestructiveDelete a firewall
-
delete_firewall_deviceDestructiveDelete a device from a specific firewall
-
delete_imageDestructiveDelete an Image
-
delete_image_sharegroupDestructiveDelete an image share group
-
delete_instanceDestructiveDelete a Linode instance
-
delete_instance_configDestructiveDelete a configuration profile for a Linode instance
-
delete_instance_diskDestructiveDelete a disk for a Linode instance
-
delete_ipv4_addressDestructiveDelete an IPv4 address from a Linode instance
-
delete_ipv6_rangeDestructiveDelete an IPv6 range
-
delete_kubernetes_clusterDestructiveDelete a Kubernetes cluster
-
delete_kubernetes_control_plane_aclDestructiveDelete the control plane ACL configuration for a Kubernetes cluster
-
delete_kubernetes_kubeconfigDestructiveDelete (revoke) the kubeconfig for a Kubernetes cluster
-
delete_kubernetes_nodeDestructiveDelete a node from a Kubernetes cluster
-
delete_kubernetes_node_poolDestructiveDelete a node pool from a Kubernetes cluster
-
delete_kubernetes_service_tokenDestructiveDelete the service token for a Kubernetes cluster
-
delete_linode_interfaceDestructiveDelete an interface from a Linode
-
delete_log_destinationDestructiveDelete a log destination
-
delete_log_streamDestructiveDelete a log stream
-
delete_longview_clientDestructiveDelete a Longview client
-
delete_mysql_instanceDestructiveDelete a MySQL database instance
-
delete_nodebalancerDestructiveDelete a NodeBalancer
-
delete_notification_channelDestructiveDelete a notification channel
-
delete_oauth_clientDestructiveDelete an OAuth client
-
delete_objectDestructiveDelete an object from an Object Storage bucket
-
delete_object_storage_bucketDestructiveDelete an Object Storage bucket
-
delete_object_storage_bucket_certificateDestructiveDelete SSL/TLS certificate for an Object Storage bucket
-
delete_object_storage_keyDestructiveDelete an Object Storage key
-
delete_placement_groupDestructiveDelete a placement group
-
delete_postgresql_connection_poolDestructiveDelete a connection pool from a PostgreSQL database instance
-
delete_postgresql_instanceDestructiveDelete a PostgreSQL database instance
-
delete_resource_lockDestructiveDelete a resource lock
-
delete_sharegroup_tokenDestructiveDelete a sharegroup token
-
delete_ssh_keyDestructiveDelete an SSH key from your profile
-
delete_stackscriptDestructiveDelete a StackScript
-
delete_tagDestructiveDelete a Tag
-
delete_userDestructiveDelete a user
-
delete_vlanDestructiveDelete a VLAN
-
delete_volumeDestructiveDelete a volume
-
delete_vpcDestructiveDelete a VPC
-
delete_vpc_subnetDestructiveDelete a subnet in a VPC
-
remove_nodebalancer_configDestructiveremove a port configuration from a NodeBalancer
-
remove_nodebalancer_nodeDestructiveRemove a node from a NodeBalancer port config
-
remove_sharegroup_imageDestructiveRevoke access to a shared image in a share group
-
remove_sharegroup_memberDestructiveRevoke a membership token from a share group
-
revoke_authorized_appDestructiveRevoke access for an authorized OAuth app
-
revoke_trusted_deviceDestructiveRevoke trusted status for a device
-
rebuild_instanceDestructiveRebuild a Linode instance
-
regenerate_kubernetes_clusterDestructiveRegenerate a Kubernetes cluster
-
suspend_mysql_instanceDestructiveSuspend a MySQL database instance
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.