High-risk tools in Starfield
12 of the 233 tools in Starfield are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
adrata_ai_tool_executeExecuteExecute the same governed AI CRM ToolDispatcher path used by Adrata chat. Free reads run directly. Reads that can spend external data credits return a spend hold; execute one on...
-
adrata_api_requestExecuteGoverned low-level Adrata API request. Read calls run directly except sensitive denied surfaces. Writes default to dry-run; a live write requires dryRun:false plus approved:true...
-
attribute_partner_to_dealExecuteCredit a partner on an opportunity. attributionType is STRATEGIC (incremental revenue not won without the partner) or INFLUENCED (facilitation). motion: co_sell, joint_solution,...
-
build_pursuit_command_centerExecuteBuild or refresh Adrata’s persistent, evidence-linked Pursuit command center for one enterprise account. Composes the active opportunity, structured MEDDPICC, buyer room and pat...
-
draft_workflowExecuteCreate an Adrata workflow draft manifest that can be saved as adrata.workflow.json, validated, dry-run, deployed, and replayed without opening the app.
-
dry_run_workflowExecuteDry-run a workflow draft through the control plane. If the API is unavailable, returns a local policy/audit execution plan for review.
-
record_partner_consumptionExecuteRecord committed vs consumed revenue for a partner over a period. Signature != revenue: in a consumption business revenue is realized as usage grows, and partners drive it. driv...
-
replay_workflow_runExecuteReplay or plan replay for a workflow run. Defaults to dry-run; live replay remains policy/audit gated.
-
request_deploymentExecuteRequest that the Adrata control plane deploy a custom integration or extension. The manifest is validated locally first; the request is only sent if validation passes. Activatio...
-
request_provider_action_executionExecuteRequest a scoped provider action execution without registering every provider endpoint as a separate MCP tool. Defaults to dry-run and returns policy, scope, billing, risk, and ...
-
request_workflow_deploymentExecuteRequest hosted deployment for a workflow. Requires a prior dry-run id and keeps activation gated on policy pass and audit logging.
-
warmup_emailExecuteStart or stop gradual sending warmup for an email account. Warmup builds sender reputation by slowly increasing send volume. Enterprise only.
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.