High-risk tools in Actual
2 of the 64 tools in Actual are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
actual_bank_syncExecuteTrigger 3rd party bank sync (GoCardless, SimpleFIN) for linked bank accounts. Returns immediately with an error if no bank-linked accounts are found. When bank-linked accounts e...
-
actual_query_runExecuteExecute SQL queries for advanced financial data analysis. **RECOMMENDED: Use SQL syntax** - Most reliable and well-tested format. SQL SYNTAX (Preferred): SELECT [fields] FRO...
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.