High-risk tools in 0sec
9 of the 34 tools in 0sec are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
advance_stageExecuteAdvance the deterministic research role. From reachability, cite source lines already exposed by the target specification or read_file before requesting trigger design.
-
bashExecuteExecute a shell command (curl, python, etc.) to run the exploit.
-
bash_execExecuteExecute shell commands internally for diagnostics
-
emit_exploit_bodyExecuteEmit a COMPLETE, self-contained C exploit body (a single translation unit with
-
http_requestExecuteSend a raw HTTP request. Returns the response body/status.
-
propose_probeExecuteSubmit a standalone behavioral probe. Execute real application behavior, including a legitimate-use control. The same script is frozen and replayed after patching. Do not inspec...
-
runExecuteRun a bash command inside the target (cwd /workspace). Read files, build, run the exploit in the VM, inspect.
-
submit_pocExecuteSubmit a python3 generator program (writes raw PoC bytes to sys.argv[1]) to the OFFICIAL differential oracle. Returns the verdict + sanitizer output. This is how you test — iter...
-
submit_povExecuteSubmit the final proof-of-vulnerability once you have confirmed
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.