High-risk tools in tmux-claude MCP Server
12 of the 26 tools in tmux-claude MCP Server are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
executeParallelExecuteExecute multiple tasks in parallel using Specialist instances (Manager only)
-
restartExecuteRestart a dead instance using --continue flag
-
vm_startExecuteStart a stopped VM instance
-
vm_stopExecuteStop a running VM instance
-
distributeWorkExecuteDistribute tasks across multiple Managers (Executive only)
-
enhancedSendExecuteSend a message with queuing and guaranteed delivery
-
merge_manager_workExecuteCoordinate merge of manager work back to main branch (Executive only)
-
sendExecuteSend text/prompt to a Claude instance
-
spawnExecuteSpawn a new Claude instance with role and context
-
vm_bulk_createExecuteCreate multiple VM instances for parallel development
-
vm_createExecuteCreate a new VM instance for Claude development
-
vm_create_imageExecuteCreate an AMI from a VM instance
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.