High-risk tools in Cocos
20 of the 157 tools in Cocos are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
align_view_with_nodeExecuteApply selected node position and angle to current view
-
build_projectExecuteBuild the project
-
change_gizmo_toolExecuteChange Gizmo tool
-
change_view_mode_2d_3dExecuteChange 2D/3D view mode
-
execute_component_methodExecuteExecute method on component
-
execute_scene_scriptExecuteExecute scene script method
-
execute_scriptExecuteExecute JavaScript in scene context
-
focus_camera_on_nodesExecuteFocus scene camera on nodes
-
listen_broadcastExecuteStart listening for specific broadcast messages
-
open_asset_externalExecuteOpen asset with external program
-
open_preferences_settingsExecuteOpen preferences settings panel
-
refresh_assetsExecuteRefresh asset database
-
refresh_reference_imageExecuteRefresh reference image display
-
reimport_assetExecuteReimport an asset
-
run_projectExecuteRun the project in preview mode
-
scene_snapshot_abortExecuteAbort scene snapshot creation
-
soft_reload_sceneExecuteSoft reload current scene
-
start_preview_serverExecuteStart preview server
-
stop_listeningExecuteStop listening for specific broadcast messages
-
stop_preview_serverExecuteStop preview server
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.