High-risk tools in Mcp Windows
95 of the 441 tools in Mcp Windows are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
wifi_adapter_resetExecuteReset WiFi adapter (disable and re-enable)
-
mysql_diagnostics_infoExecuteRun comprehensive diagnostics and retrieve aggregated info.
-
navigate_to_urlExecuteNavigate to a specific URL
-
office_execute_commandExecuteExecute Office.js command for Microsoft 365 apps
-
run_commandExecuteRun a Windows command with enhanced safety checks.
-
service_controlExecuteControl Windows service (start, stop, restart, enable, disable)
-
spotify_play_genreExecuteStart a playlist for a specific genre
-
start_ml_monitoringExecuteStart comprehensive ML monitoring and data collection
-
start_web_automationExecuteStart web browser automation (requires Chrome and ChromeDriver)
-
stop_auto_retrainingExecuteStop the automated daily ML model retraining scheduler
-
stop_ml_monitoringExecuteStop continuous ML monitoring
-
system_file_checkerExecuteRun System File Checker (SFC scan)
-
task_scheduler_controlExecuteControl scheduled tasks (start, stop, enable, disable)
-
trigger_manual_retrainingExecuteManually trigger ML model retraining (bypasses schedule)
-
wifi_stop_hotspotExecuteStop the WiFi hotspot
-
wifi_troubleshootExecuteRun WiFi troubleshooting diagnostics
-
advanced_network_diagnosticsExecuteAdvanced network diagnostics and troubleshooting
-
advanced_process_managerExecuteAdvanced process management with filtering and bulk operations
-
auto_optimize_systemExecuteAutomatically optimize system based on ML predictions
-
automate_calculatorExecuteAutomate Calculator to perform calculations
-
encode_decode_base64ExecuteEncode or decode text using Base64
-
find_and_click_elementExecuteFind and click an element on the webpage using Chrome automation
-
first_photoExecuteGo to first photo in Lightroom
-
flush_dns_cache_and_verifyExecuteFlush Windows DNS cache and verify the operation
-
flush_dns_cache_quickExecuteFlush Windows DNS cache (quick)
-
focus_windowExecuteFocus on a specific window by title (partial match)
-
last_photoExecuteGo to last photo in Lightroom
-
monitor_display_modeExecuteChange display mode (duplicate, extend, internal, external)
-
monitor_resolution_changeExecuteChange display resolution and refresh rate
-
mysql_analyze_tableExecuteAnalyze a table to update key distribution statistics.
-
mysql_auto_index_rebuild_schedulerExecuteAutomatically schedule index rebuilds based on usage patterns.
-
mysql_flush_logsExecuteFlush MySQL logs.
-
mysql_flush_privilegesExecuteFlush MySQL privileges to reload grant tables.
-
mysql_flush_tablesExecuteFlush MySQL tables.
-
mysql_grant_privilegesExecutemysql_grant_privileges
-
mysql_optimize_tableExecuteOptimize a table to reclaim unused space and defragment.
-
mysql_query_analysisExecuteComprehensive query analysis including execution plan and recommendations.
-
mysql_repair_tableExecuteRepair a possibly corrupted table.
-
network_security_scanExecutePerform network security scanning and analysis
-
next_photoExecuteGo to next photo in Lightroom
-
play_favorite_songExecutePlay user's favorite song on YouTube
-
previous_photoExecuteGo to previous photo in Lightroom
-
rebuild_table_indexesExecuteRebuild all indexes for a table.
-
record_user_actionExecuterecord_user_action
-
scan_open_portsExecuteScan for open ports on a target host
-
service_managerExecuteservice_manager
-
smart_music_actionExecuteSmart music actions - play favorite, open music service, etc.
-
spotify_maximize_windowExecuteMaximize Spotify window
-
spotify_minimize_windowExecuteMinimize Spotify window
-
spotify_muteExecuteMute Spotify audio
-
spotify_next_trackExecuteSkip to the next track in Spotify
-
spotify_pauseExecutePause playback in Spotify
-
spotify_playExecutePlay the current track in Spotify
-
spotify_play_based_on_moodExecutePlay a playlist matching a mood
-
spotify_play_podcastExecutePlay a specific podcast
-
spotify_play_song_by_artistExecutePlay a specific song by artist
-
spotify_previous_trackExecuteReturn to the previous track in Spotify
-
spotify_repeat_toggleExecuteToggle repeat mode
-
spotify_search_and_play_trackExecuteSearch for a track by name and play it immediately
-
spotify_seek_to_timeExecuteSeek to a specific timestamp in the track
-
spotify_shuffle_toggleExecuteToggle shuffle mode
-
spotify_toggle_play_pauseExecuteToggle between play and pause in Spotify
-
spotify_unmuteExecuteUnmute Spotify audio
-
train_behavior_modelExecuteTrain the user behavior prediction model
-
train_system_optimizerExecuteTrain the system optimization model
-
windows_feature_controlExecuteEnable or disable Windows optional features
-
automate_notepadExecuteAutomate Notepad actions (open, type, save, etc.)
-
click_at_coordinatesExecuteClick at specific screen coordinates
-
click_image_if_foundExecuteFind and click an image on the screen
-
close_web_automationExecuteClose the web automation browser
-
create_automation_workflowExecuteCreate and execute a custom automation workflow
-
create_functionExecutecreate_function
-
drag_and_dropExecuteDrag from start coordinates to end coordinates
-
move_mouseExecuteMove mouse to specified coordinates
-
mysql_lock_tablesExecuteLock tables for the current session.
-
mysql_unlock_tablesExecuteUnlock all tables for the current session.
-
open_app_with_urlExecuteOpen an application with optional URL/parameters
-
open_youtube_with_searchExecuteOpen YouTube and search for a specific song/video
-
scroll_screenExecuteScroll the screen in specified direction (up/down)
-
send_keyboard_shortcutExecuteSend keyboard shortcut (e.g., 'ctrl+c', 'alt+tab', 'win+r')
-
setup_auto_daily_retrainingExecuteSet up automated daily ML model retraining with intelligent scheduling
-
spotify_click_elementExecuteClick specified element in Spotify
-
spotify_close_appExecuteQuit Spotify application
-
spotify_open_discover_weeklyExecuteOpen Discover Weekly playlist
-
spotify_open_release_radarExecuteOpen Release Radar playlist
-
spotify_press_keyExecutePress keyboard shortcut in Spotify
-
spotify_resume_last_playedExecuteResume last playlist or album
-
spotify_scroll_playlistExecuteScroll in a playlist view
-
spotify_set_volumeExecuteSet volume to a specific percentage (0-100)
-
type_in_elementExecuteType text into an element on the webpage
-
type_textExecuteType text with specified interval between characters
-
wifi_connect_profileExecuteConnect to a saved WiFi profile
-
wifi_create_hotspotExecuteCreate a WiFi hotspot (requires administrative privileges)
-
wifi_disconnectExecuteDisconnect from current WiFi network
-
wifi_power_managementExecuteShow and manage WiFi adapter power settings
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.