High-risk tools in Meridian
9 of the 235 tools in Meridian are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
execute_batchExecute[SUPPORT] 627187b8 — run a HOMOGENEOUS batch of management writes (all entries the SAME operation) with real atomic-or-independent semantics. Every entry in ``entries`` is valid...
-
prospect_symbolExecute[SUPPORT] 2ce5bc76 — ROBUST symbol prospecting with a three-rung fallback chain: tries codebase__search_graph FIRST (fast, graph-indexed); when it returns zero results OR the ca...
-
run_verificationExecute[SUPPORT] 0e973e52 — run the project's stored test_cmd on YOUR local machine via the tunnel and return a REAL, structured result — not self-reported. Fields: {exit_code, passed,...
-
run_watchlist_queryExecute[SUPPORT] b924fd7c — re-run a saved watchlist query and diff its results against everything already captured for it. Every newly-seen result (matched by a per-source stable id —...
-
start_experiment_runExecute[SUPPORT] 3f6b8715 — start a new active run (trial) under an experiment. Passing pivot_parent_run_id (which must belong to the SAME experiment) auto-writes a 'pivot' experiment_...
-
start_remote_taskExecute[SUPPORT] 32d3d5de — Launch a long-running job on a remote host (e.g. a rented GPU pod) over a short-lived SSH connection used ONLY to start it, never held open: the command run...
-
start_research_runExecute[SUPPORT] a5343387 — start a bounded, ephemeral research/scratch run: an ADJACENT primitive for disposable subagent probes that should not need a formal sprint item, a formal cl...
-
start_sessionExecuteRegister a session and return orientation. Compact by default (session_id, sprint focus + status counts, 3 recent tasks, board_change count) to keep an executor's context small....
-
start_wave_runExecute[SUPPORT] 2a654cb0 — DURABLE WAVE STATE: open a wave run before dispatching a parallel wave. Returns an immutable wave_run_id pinned to the canonical expanded board snapshot (re...
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.