High-risk tools in DeepSeek MCP Server
3 of the 7 tools in DeepSeek MCP Server are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
chat_completionExecutePrimary DeepSeek V4 chat tool for single-turn and multi-turn generation. Defaults to
-
completionExecuteDeepSeek V4 Pro FIM completion tool for prompt/suffix fill-in-the-middle workflows. Defaults to
-
create_responseExecuteCreate a stateless DeepSeek V4 response using the native OpenAI-compatible Responses API. Defaults to
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.