High-risk tools in AIR SDK
2 of the 5 tools in AIR SDK are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
execute_capabilityExecuteStep 2 of 3: Get execution guidance for a specific capability. Returns the optimal path: API fast-path, pre-verified macro steps, selector hints, or context for unverified capab...
-
report_outcomeExecuteREQUIRED: Report the outcome after executing ANY browser action via AIR. This is the final step of every browse \u2192 execute \u2192 report workflow. Without your report, the a...
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.