High-risk tools in Doit
9 of the 238 tools in Doit are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
async_run_inlineExecuteManage Cloud Analytics reports and get reports data in JSON format. Submits an async report execution job using an inline configuration. Returns 202 immediately with a Location ...
-
async_run_report_by_idExecuteManage Cloud Analytics reports and get reports data in JSON format. Submits an async execution job for a saved report identified by ID. Returns 202 immediately with a Location h...
-
build_cloud_flowExecuteUse this when the user wants to build a brand-new CloudFlow automation from scratch using natural language. Creates the draft before planning, so flowId can be returned even if ...
-
refine_cloudflowExecuteRefines an existing CloudFlow using natural language. Streams progress and returns the answer and conversationId; normally no flowId is returned. A plan or clarification questio...
-
resend_signup_verificationExecuteStart a Cloud Intelligence trial for an organization that is not yet a DoiT customer. These operations require no API key: they are rate limited, idempotent, and provision nothi...
-
run_queryExecuteUse this when the user wants to analyze cloud costs, generate a cost breakdown, view spending trends, or run a custom analytics query across their cloud providers. Runs the conf...
-
stop_cloudflow_flowExecuteManage CloudFlow. Stops the run currently in progress for the given flow. The run is identified from the flow alone — no run ID is needed, since a flow can only have one run act...
-
trigger_cloud_flowExecuteTriggers a published CloudFlow with a webhook trigger by flow ID or trigger URL. Executes real actions immediately and returns executionLink. Drafts fail with 403, flows without...
-
trigger_cloudflow_flowExecuteManage CloudFlow. Starts a run of a **published** flow whose first node is a webhook, scheduled, or manual trigger. A draft flow is rejected with `422` — use `actions/test-run` ...
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.