High-risk tools in Cutpilot
21 of the 219 tools in Cutpilot are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
activate_timelineExecuteSwitch the active sequence used by editing, preview, validation, and rendering tools.
-
apply_natural_language_editExecuteApply an explicitly reviewed natural-language edit plan as one validated project change. Destructive actions remain visible in the plan and approval is mandatory.
-
apply_talking_head_directorExecuteApply a reviewed talking-head director plan to linked speaker video/dialogue, semantic B-roll, voice cleanup, karaoke captions, music ducking, and export preset.
-
cutpilot_apply_planExecuteHigh-level reviewed apply: execute an explicitly approved built-in AI director or revision plan as one snapshot-protected edit.
-
cutpilot_finish_videoExecuteHigh-level finishing gate: audit the current project and, only when approved and release-ready, submit a background MP4 export.
-
install_remotion_projectExecuteInstall a reviewed Remotion project
-
open_review_sessionExecuteStart a token-protected localhost review UI for the real CutPilot project and optional rendered preview.
-
razor_all_tracksExecuteSplit every unlocked item crossing an absolute timeline time.
-
recover_background_tasksExecuteDetect abandoned queued/running tasks after a restart and optionally resubmit them safely as linked retries.
-
render_audioExecuteRender the active timeline
-
render_edit_planExecuteRender a CutPilot JSON project to a local MP4 using FFmpeg.
-
render_glsl_batchExecuteRender multiple validated GLSL video jobs concurrently through independent local Chrome WebGL1 workers, preserving a durable batch manifest and per-job errors.
-
render_motion_graphics_scenesExecuteRender approved MG scenes into editable background and overlay SVG/PNG assets with keyframes, transitions, and validated GLSL presets.
-
render_product_promo_cardsExecuteRender only reviewed product claims and CTA cards as safe editable SVG Motion Graphics on V3 Text & CTA.
-
render_projectExecuteRender the active multitrack CutPilot timeline with mixed audio and optional burned captions.
-
render_remotion_compositionExecuteRender a real Remotion composition or still with input props, codec, CRF, concurrency, and optional frame range through the official Remotion bundler and renderer.
-
retry_background_taskExecuteRetry a terminal background task as a new traceable task linked to the original.
-
submit_background_taskExecuteSubmit a persistent non-blocking CutPilot task. Supported kinds: ${BACKGROUND_TASK_KINDS.join(
-
submit_delivery_packExecuteSubmit background MP4 exports for selected delivery-variant timelines; every job snapshots and renders its explicit timeline instead of relying on the active sequence.
-
submit_export_jobExecuteStart a detached, persistent local export without blocking the Codex session. Supports video, audio, editable NLE interchange, and experimental Jianying drafts.
-
submit_generationExecuteSubmit a persistent image/video/music/SFX job through offline fixtures, OpenAI image, generic HTTP, or configured Seedance/Kling/Mureka/SFX bridges.
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.