High-risk tools in instantKOM MCP Server
3 of the 245 tools in instantKOM MCP Server are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
approve_device_flowExecuteApprove or deny a device authorization request (requires JWT authentication).
-
start_device_flowExecuteStart an RFC 8628 device authorization flow.
-
switch_tenantExecuteSwitch the active tenant/environment at runtime. Changes which API endpoint, credentials, and tools are available. Use list_tenants to see available options.
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.