High-risk tools in Mapi Agent Memory
28 of the 252 tools in Mapi Agent Memory are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
apply_escalation_reactionsExecuteapply_escalation_reactions
-
apply_memory_lifecycle_remediationExecuteExecute the guarded legacy lineage remediation after explicit confirmation.
-
apply_memory_pointer_lifecycle_remediation_executionExecuteExecute an explicitly approved frozen pointer-lifecycle remediation manifest.
-
backfill_semantic_embeddingsExecuteGeneruje embeddingi dla wspomnień które jeszcze ich nie mają.
-
gemma_lms_loadExecuteLoad configured Gemma model through the LM Studio CLI.
-
gemma_lms_unloadExecuteUnload configured Gemma model through the LM Studio CLI.
-
gemma_worker_run_jobExecutegemma_worker_run_job
-
gemma_worker_run_taskExecutegemma_worker_run_task
-
git_pushExecutePush the current branch or an explicit branch.
-
git_statusExecuteRun git status --short.
-
preview_memory_pointer_lifecycle_remediation_execution_rollbackExecutePreview exact snapshot-based rollback of a pointer-lifecycle remediation run.
-
preview_undo_runExecutepreview_undo_run
-
query_sqlExecutequery_sql
-
rollback_memory_hygiene_runExecuterollback_memory_hygiene_run
-
rollback_memory_lifecycle_remediationExecuteExecute guarded snapshot-based rollback for a legacy remediation run.
-
rollback_memory_supersession_runExecuteExecute guarded rollback for a Memory v3 supersession apply run.
-
run_conflicts_v1Executerun_conflicts_v1
-
run_consolidation_v1Executerun_consolidation_v1
-
run_escalation_checkExecuterun_escalation_check
-
run_powershellExecuteRun a PowerShell script from the dev MCP server.
-
run_pytestExecuteRun pytest from the repository root.
-
run_sandman_aiExecuteSandman AI (wykonanie) — używa LM Studio (Qwen) do oceny wspomnień i wprowadza zmiany.
-
run_sandman_gemma_hygieneExecuteRun Gemma-style Sandman hygiene for low-risk validated actions only. Semantic archive stays review-only.
-
run_sandman_quality_hygieneExecuteRun deterministic Sandman quality hygiene repairs with audit events.
-
run_sandman_v1ExecuteSandman V1 — archiwizacja, downgrade, duplikaty.
-
run_workshop_actionExecuteRun an action from a workshop through the compact MCP surface.
-
sandman_memory_chatExecuteSandman Memory Chat — host steruje narzędziami MAPI dla lokalnego modelu.
-
undo_runExecuteundo_run
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.