High-risk tools in GCP MCP Server
18 of the 295 tools in GCP MCP Server are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
gcp_agent_deploy_modelExecuteDeploy a model to a Vertex AI endpoint
-
gcp_bq_cancel_jobExecuteCancel a running BigQuery job
-
gcp_bq_run_queryExecuteRun a BigQuery SQL query
-
gcp_build_cancel_buildExecuteCancel a running Cloud Build build
-
gcp_build_create_buildExecuteCreate and start a new Cloud Build build
-
gcp_build_run_triggerExecuteRun a Cloud Build trigger manually
-
gcp_compute_reset_instanceExecuteReset (hard reboot) a VM instance
-
gcp_compute_start_instanceExecuteStart a stopped VM instance
-
gcp_compute_stop_instanceExecuteStop a running VM instance
-
gcp_firestore_run_queryExecuteRun a structured query on Firestore
-
gcp_functions_callExecuteCall/invoke a Cloud Function directly
-
gcp_gke_set_network_policyExecuteEnable/disable network policy for a cluster
-
gcp_kms_encryptExecuteEncrypt data using a Cloud KMS key
-
gcp_run_execute_jobExecuteExecute a Cloud Run job
-
gcp_services_batch_enableExecuteEnable multiple API services at once
-
gcp_sql_restart_instanceExecuteRestart a Cloud SQL instance
-
gcp_sql_start_replicaExecuteStart replication on a read replica
-
gcp_sql_stop_replicaExecuteStop replication on a read replica
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.