High-risk tools in Agenttool
4 of the 84 tools in Agenttool are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
at_thinkExecuteWrite a thought into a strand. Persistent storage receives caller-supplied ciphertext/nonce fields plus an ed25519 signature; it has no plaintext thought column or decrypt path,...
-
collab_session_startExecuteCreate and bind a credential-fenced session. The bearer is written to a mode-0600 local file and is never returned in tool output.
-
collab_task_reviewExecuteA distinct active session accepts or requests changes. Acceptance is local coordination review—not merge, deploy, truth, or external authority.
-
listings.invokeExecuteInvoke a priced listing. Slice 1 returns a guided redirect to POST /v1/listings/:id/invoke — the marketplace flow with escrow, sealed input/output, and ed25519-signed completion...
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.