Critical-risk tools in Todo for AI MCP Server
11 of the 244 tools in Todo for AI MCP Server are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
cancel_workflow_runDestructiveCancel a running workflow. All pending/running steps are cancelled.
-
clear_step_runtime_overrideDestructiveClear runtime overrides for a workflow step run, reverting to the workflow definition.
-
delete_agent_experienceDestructiveDelete (soft-delete) an experience record for an Agent.
-
delete_collaboration_templateDestructiveDelete a user-created collaboration template.
-
delete_knowledge_entryDestructiveDelete (invalidate) a knowledge entry.
-
delete_sandboxDestructiveDelete a sandbox policy (only if no active executions reference it).
-
delete_shared_contextDestructiveDelete a shared context entry by its ID.
-
delete_workflowDestructiveDelete a workflow definition.
-
delete_workflow_triggerDestructiveDelete a workflow trigger.
-
revoke_cross_project_agentDestructiveRevoke an Agent\
-
revoke_sandbox_executionDestructiveManually revoke (terminate) a running sandboxed execution.
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.