High-risk tools in 1Panel MCP Server
36 of the 286 tools in 1Panel MCP Server are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
build_imageExecuteBuild image
-
build_openrestyExecuteBuild OpenResty (XPack)
-
close_ollama_modelExecuteClose Ollama model connection (XPack)
-
create_containerExecuteCreate container
-
create_cronjobExecuteCreate cronjob
-
create_ollama_modelExecuteCreate Ollama model (XPack)
-
exec_commandExecuteExecute command
-
generate_host_ssh_keyExecuteGenerate host SSH key
-
install_appExecuteInstall app
-
install_environmentExecuteInstall environment
-
install_php_extensionExecuteInstall PHP extension
-
load_imageExecuteLoad image
-
load_ollama_modelExecuteLoad Ollama model (XPack)
-
mount_diskExecuteMount disk
-
operate_fail2banExecuteOperate Fail2ban (start/stop/restart)
-
operate_fail2ban_sshExecuteOperate Fail2ban SSH (start/stop/restart)
-
operate_ftpExecuteOperate FTP (start/stop/restart)
-
operate_mcp_serverExecuteOperate MCP server (XPack)
-
operate_node_moduleExecuteOperate Node module (XPack)
-
pause_containerExecutePause container
-
pull_imageExecutePull image
-
push_imageExecutePush image
-
resolve_sslExecuteResolve SSL certificate
-
restart_composeExecuteRestart compose
-
restart_containerExecuteRestart container
-
scan_clamExecuteScan with ClamAV
-
start_composeExecuteStart compose
-
start_containerExecuteStart container
-
stop_composeExecuteStop compose
-
stop_containerExecuteStop container
-
test_composeExecuteTest compose
-
test_host_connectionExecuteTest host connection
-
test_host_connection_by_infoExecuteTest host connection by info
-
unpause_containerExecuteUnpause container
-
update_php_versionExecuteUpdate PHP version
-
upgrade_containerExecuteUpgrade container
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.