High-risk tools in Hercules MCP
33 of the 45 tools in Hercules MCP are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
browser_actExecuteInteract with an element (click/fill/type/press/hover/select/check).
-
browser_cmdExecuteEscape hatch: run any agent-browser subcommand against the stealth session.
-
browser_evalExecuteRun JavaScript in the page and return the result.
-
browser_openExecuteOpen a URL in a stealth Chromium session.
-
browser_sessionExecuteManage browser sessions / live-view stream.
-
browser_waitExecuteWait for a selector / ms / text / url / load state.
-
bruteforce_hydraExecutebruteforce_hydra
-
crack_johnExecuteOffline password cracking using John the Ripper. Hashes written to temp file.
-
ctf_binwalkExecuteFirmware/archive analysis and extraction using binwalk.
-
ctf_steghideExecuteSteganography analysis and extraction via steghide.
-
fuzz_dirsExecuteDirectory brute-forcing (gobuster/ffuf).
-
metasploit_generate_payloadExecuteGenerate a payload. Tries RPC first, falls back to msfvenom CLI.
-
metasploit_manageExecuteManage Metasploit sessions and jobs.
-
metasploit_run_moduleExecutemetasploit_run_module
-
metasploit_start_listenerExecuteStart exploit/multi/handler as a background job to catch reverse shells.
-
ncatExecuteUse ncat to connect, listen, or interact with a background listener.
-
network_curlExecuteHTTP client (curl) for arbitrary web requests.
-
network_hping3ExecutePacket crafting and firewall testing (hping3).
-
nmap_run_nse_scriptExecuteRun a custom NSE script against a target.
-
nmap_scanExecuteRun nmap in quick, aggressive, port, script, or custom mode.
-
nmap_write_nse_scriptExecuteWrite custom NSE script and update DB.
-
nuclei_runExecuteRun nuclei vulnerability scanner against targets.
-
recon_amassExecuteSubdomain enumeration via amass.
-
recon_dnsExecuteRun DNS lookups with dig or bulk DNS resolution with dnsx.
-
searchsploitExecuteExploit-DB search or exploit retrieval.
-
shell_execExecuteshell_exec
-
shell_exec_backgroundExecuteRun a long shell command in the background, returning a job_id.
-
shell_kill_jobExecuteKill a running background shell job (useful for stuck commands).
-
sqlmap_runExecuteAutomated SQL injection suite. Always uses --batch.
-
system_start_new_sessionExecutesystem_start_new_session
-
system_stop_containerExecutesystem_stop_container
-
web_scanExecuteRun one web fingerprinting scanner selected by tool.
-
web_vuln_scanExecuteRun Dalfox XSS scanning or Commix command-injection scanning.
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.