High-risk tools in 20i MCP Server
20 of the 302 tools in 20i MCP Server are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
activate_vpsExecuteActivate VPS service and subservices
-
change_vps_root_passwordExecuteChange VPS root password (will reboot server)
-
clone_wordpress_stagingExecuteClone WordPress between live and staging environments
-
deploy_applicationExecuteDeploy a new runtime application (Node.js, Python, etc.)
-
deploy_website_completeExecuteDeploy a complete WordPress website with automatic setup, theme installation, content creation, and SSL configuration. This is the unified deployment tool that handles end-to-en...
-
enforce_security_complianceExecuteEnforce security compliance standards
-
install_applicationExecuteInstall an application on a hosting package
-
perform_dns_bulk_operationsExecutePerform bulk DNS operations across multiple domains
-
reboot_vpsExecuteReboot a VPS
-
recycle_application_poolExecuteRecycle Windows IIS application pool
-
request_malware_scanExecuteRequest a new malware scan for a hosting package
-
resend_domain_verification_emailExecuteResend domain verification email for a specific domain
-
resend_ssl_approval_emailExecuteResend SSL certificate approval email for domain validation
-
run_malware_scan_advancedExecuteRun advanced malware scan with comprehensive configuration
-
split_packageExecuteSplit package into multiple hosting packages
-
start_vpsExecuteStart a stopped VPS
-
stop_vpsExecuteStop a running VPS
-
test_scheduled_taskExecuteTest scheduled task execution
-
update_wordpressExecuteUpdate WordPress to the latest version
-
wordpress_search_replaceExecutePerform WordPress search and replace operation
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.