High-risk tools in Freedom Mcp
19 of the 238 tools in Freedom Mcp are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
audit_brand_visibilityExecuteAudit whether Freedom OS appears in AI-generated search results. Sends a search query to external LLMs (Claude, Grok, Gemini, Perplexity) and checks each response for brand ment...
-
browse_urlExecuteBrowse a web page in a real browser and take a screenshot. Returns page content and a screenshot image. Use when you need to SEE what a page looks like (visual audit, brand chec...
-
challenge_as_customerExecuteRun your deliverable past the company's customer truth: REAL Customer Evidence first (when stored), then generated ICP as labeled simulation. Returns honest feedback — what woul...
-
decide_command_center_itemExecuteApprove or deny a Command Center card. This processes the decision through the full approval pipeline including trust scoring, autopilot evaluation, skill learning, and delivera...
-
deliberateExecuteRun an adversarial deliberation on a decision. Multiple AI perspectives argue opposing positions over multiple rounds, iteratively strengthening arguments, and converge on a rec...
-
generate_image_xaiExecuteGenerate or EDIT an image using xAI Imagine. Handles ALL image styles: photorealistic, illustrations, flat graphics, icons, banners, concept art. Supports 2K resolution. Provide...
-
generate_vector_imageExecuteGenerate a native SVG vector image using Recraft V4 Pro Vector. The ONLY tool that outputs true SVG with editable paths. Best for logos, icons, brand marks, vector illustrations...
-
generate_video_veoExecuteGenerate a high-fidelity cinematic video using Google Veo 3.1 (5 credits). Premium quality with realistic physics and cinematic lighting. Use ONLY for final deliverables — landi...
-
hire_agentExecuteDEPRECATED: Redirects to interview_for_hire. All hiring now requires context gathering to create a proper JD. Use interview_for_hire directly when user wants to hire someone. [...
-
hire_agent_with_contextExecuteHire a new specialist with full hiring context gathered from the interview. Use AFTER walking through the interview phases. The richer the context, the better the agent. [sensi...
-
invoke_integrationExecuteExecute a tool on a connected MCP integration. First use list_integrations to discover available tools. [outbound-tier — EVERY call needs a manager's approval (per-send human r...
-
posthog_hogqlExecuteRun an arbitrary HogQL (SQL) query against PostHog data. Use for custom analysis not covered by other tools. Only works if PostHog is connected.
-
request_attention_spawnExecuteRequest a NEW local coding session from voice/chat (tab spawn). Queues a sticky for the desk launcher on THIS operator's machine (host must run attention-launcher). Use when the...
-
resolve_workExecuteMark a shared work-graph item resolved — verified (default), published, or cancelled. In the full system, resolving an item cascades to unblock items that depend on it, so this ...
-
run_quality_checkExecuteEvaluate content or media against your ICP persona using Gemini 3.1 Pro vision. Actually SEES images and WATCHES videos. Returns quality scores (1-10) across 6 dimensions + spec...
-
run_tacticExecuteRun a saved Play (growth_tactics) for the company operator or agent — dispatch the next unit as a one-off draft activity, or dry-run a Play brief with suggest_only. Use when the...
-
send_emailExecuteSend an outbound email via the company's Resend connection. Resolves the per-company Resend API key + from identity, then sends to a single recipient. Honors the do_not_contact ...
-
toggle_agent_scheduleExecutePause or resume an agent's scheduled activities — the whole activity plan, or a single activity via activity_name. Pausing stops future scheduler-dispatched runs until resumed; ...
-
trigger_agent_activityExecuteTrigger a specific agent to run a specific activity immediately. This dispatches the work and returns — it does not wait for the activity to complete. Use this to direct agents ...
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.