High-risk tools in Bring Your AI
2 of the 7 tools in Bring Your AI are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
preview_build_setupExecuteFree no-data preview for building a user's first Claude Code or Codex setup. Does not accept GitHub handles, generated memories, mappings, or file content.
-
start_checkoutExecuteStart checkout. With payment_mode=stripe_spt plus shared_payment_granted_token and buyer_email, settles a Stripe PaymentIntent and returns the signed license without opening a b...
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.