High-risk tools in Zuckerbot
7 of the 59 tools in Zuckerbot are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
zuckerbot_launch_campaignExecuteLaunch a draft campaign on Meta (Facebook/Instagram). THIS IS THE MONEY ENDPOINT — it creates real ads on the user's Meta ad account and immediately begins spending their budget...
-
zuckerbot_launch_portfolioExecuteLaunch all tiers in an audience portfolio on Meta. Creates separate Meta campaigns for each tier (prospecting, retargeting, reactivation) using the portfolio's budget allocation...
-
zuckerbot_portfolio_performanceExecuteFetch live Meta performance and downstream CAPI attribution for a launched audience portfolio. Returns enriched tier rows with ad breakdowns, daily metrics, CPA vs. target compa...
-
zuckerbot_quickstartExecuteShow the current ZuckerBot authentication mode (demo vs authenticated), the Free/Pro/Scale billing tiers, setup instructions if not yet configured, and the recommended tool flow...
-
zuckerbot_rebalance_portfolioExecuteDry-run or execute a budget rebalance across portfolio tiers based on each tier's actual vs. target CPA. With dry_run=true (default) returns recommendations without making chang...
-
zuckerbot_recommend_campaign_structureExecuteGenerate a campaign structure recommendation: audience tiers, budget allocation, creative mix. For accounts WITH history: uses Claude to generate data-driven recommendations. Fo...
-
zuckerbot_tag_creativeExecuteTag Meta ads with creative attributes (hook type, visual style, product focus, CTA type, copy tone, setting) by providing ad metadata and optional asset URLs. ZuckerBot uses Cla...
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.