High-risk tools in Nitrostack
75 of the 697 tools in Nitrostack are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
accept_offerExecuteAccept one unexpired offer returned by request_compute. Only this explicit second step may materialize a live environment, and an offer can be accepted at most once.
-
advance_applicationExecuteFAST PATH: after record_consent, run the entire post-consent chain in ONE call — verify_kyc, screen_fraud,
-
analyze_material_healthExecuteVision model checks uploaded photos against declared type. Flags contamination, rust, degradation. Outputs grade A/B/C with advisory flags. Runs autonomously on listing.created ...
-
analyze_videoExecuteAnalyze uploaded video metadata, extract frames, run YOLOv8 object detection, and store detected events
-
approve_actionExecuteApprove a queued high-risk action and execute it against live state. Use the action_id returned by the originating tool call.
-
audit_pizza_shopsExecuteRuns a quality audit across all pizza shops.
-
call_toolExecuteRoute a tool call through Sentinel Gateway\
-
chat_architectExecuteChat with the Foundry Architect to get help with code.
-
check_admin_requestExecuteEvaluate a request against the enterprise policy tree and make a definitive decision.
-
check_latencyExecutePings a host (default 8.8.8.8) to check network latency and packet loss — a quick way to tell if lag is a network problem.. CRITICAL: Never output
-
compute_affordabilityExecuteCompute net income, proposed EMI, FOIR and DTI from the pulled bureau + bank data. Run after pull_bureau and fetch_bank_statements.
-
cordon_nodeExecuteMark a node unschedulable. SAFETY-ENFORCED: refuses if it would strand all workloads.
-
decideExecuteEvaluate evidence fusion and issue policy decision for transaction
-
deploy_canaryExecuteInitiates a progressive canary deployment for a microservice using Argo Rollouts-style traffic splitting. HIGH RISK — queued for human approval. Automatically advances traffic f...
-
emergency_stopExecuteLocks the robot movement state immediately (E-Stop) or clears the lock to resume AUTO mode.
-
evaluate_consultation_taskExecuteLong-running MCP task to orchestrate end-to-end clinical consultation evaluation.
-
evaluate_scenario_agentExecuteEvaluates state event parameters for Decision Twin multi-agent workflow and returns agent blackboard state and proposal.
-
evaluate_transactionExecuteAlias for evaluateTransaction: Executes full multi-factor TBML evaluation pipeline.
-
evolve_logicExecuteRuns the full autonomous logic-evolution loop for an environmental shift as a long-running
-
execute_approved_planExecuteStart the approved plan in safe simulation mode and monitor controlled execution.
-
execute_commandExecuteExecute an argument vector inside an active environment owned by the authenticated agent. No shell is inserted; pass the executable as argv[0]. Output and runtime are bounded.
-
execute_safe_motionExecutePlans a multi-waypoint path and executes a safe robot trajectory with CBF interception.
-
execute_safe_movementExecutePlans a multi-waypoint path and executes a safe robot trajectory with step-by-step Control Barrier Function (CBF) interception.
-
execute_safe_rollbackExecuteExecute a safe Kubernetes rollback to the previous stable version.
-
execute_security_patchExecuteGenerate executable AWS CLI or Terraform commands to fix a specific security finding
-
flush_dnsExecuteFlushes the local DNS resolver cache — fixes sites that
-
foundry_start_empty_projectExecuteStarts a blank project for collaborative workspace
-
generate_networkExecuteStep 1: Dynamically geocode area/neighborhood names (e.g.
-
githubExecutePerform GitHub operations
-
gmail_send_emailExecuteSend an email using the configured Gmail account.
-
handle_requestExecuteMain AIDE router. Takes a natural language request and decides whether to schedule a meeting, assign a task, or run admin checks. Returns a structured RouterOutput.
-
inject_environmental_shiftExecuteManually reports a new environmental shift for the swarm to react to (for demo/testing). Adds it to the active shift list so evolve_logic or run_mutation_cycle can then resolve it.
-
intelligent_source_materialsExecuteFull AI procurement pipeline. For each material: progressive radius search (10→25→50→75→100km), weighted supplier scoring (distance + price + grade + trust + quantity), industri...
-
isolate_compromised_nodeExecuteQuarantines a network node suspected of compromise. HIGH RISK — queued for human approval. Confirm the node is not serving live traffic first.
-
kubernetesExecutePerform Kubernetes operations
-
life_event_roadmapExecuteBuild an ordered plan for a life change: starting a first job, getting married,
-
loginExecuteLogin with email and password
-
orchestrate_clinical_briefingExecuteMain entry point for multi-agent clinical decision support graph. Parses transcript, triggers specialized agents, and compiles live clinical briefing.
-
prioritize_engineering_branchExecuteEscalates a codebase branch for immediate compute priority and human review. HIGH RISK — queued for human approval.
-
query_neon_databaseExecuteExecute a raw SQL query against the Neon PostgreSQL database to retrieve sensor logs and historical data. Returns up to 100 rows.
-
refreshPlatformsExecuteTriggers a re-sync across all platform channels
-
remediate_security_leakExecuteApply the automated fix, enforce S3 bucket encryption/access blocks, and resolve the GitHub P1 ticket automatically.
-
restart_explorerExecuteRestarts the Windows Explorer process (windows.exe / taskbar / file explorer). Fixes a frozen taskbar, unresponsive Start menu, or ghost icons without a full reboot — a classic ...
-
retry_notificationExecuteRetry a failed notification.
-
rollback_deploymentExecuteRoll a deployment back to its previous revision (equivalent to kubectl rollout undo).
-
run_all_safety_checksExecuteRuns ALL 8 safety checks (drug interactions, allergy, disease, age, renal, pregnancy, duplicate therapy, and AYUSH herb-drug) in a single call. Returns pre-formatted check resul...
-
run_attackExecuteRun a simulated attack scenario to demonstrate Sentinel Gateway\
-
run_attack_loopExecuteExecute the provenance-guarded red-team attack loop.\n\n
-
run_campaignExecuteLaunch a full autonomous red-team campaign. Evaluates mutated prompts in a continuous loop.
-
run_decision_cycleExecuteRuns a full Decision Twin negotiation cycle for a raw manufacturing event object. Unlike run_decision_twin_orchestrator (flat params), this accepts the event object directly and...
-
run_decision_twin_orchestratorExecuteTriggers the multi-agent Decision Twin orchestrator for manufacturing & Industry 4.0 anomalies. Dynamically activates Planner, Plant Manager, Sensor, Maintenance, Memory, Produc...
-
run_fraud_pipelineExecuteRun the deterministic multi-agent fraud pipeline: ingest a ticket, generate Agent 1 triage, fan out to Agent 2 assignment and Agent 3 legal guidance, then return a dashboard-rea...
-
run_full_demoExecuteRun the complete demo sequence: setup servers → configure policies → normal traffic → tool poisoning attack → RBAC violation. Shows the full security pipeline in action.
-
run_full_secops_auditExecuteExecute full audit: scan inventory, calculate waste, generate GitHub issue, and post Slack alert card in a single atomic step
-
run_full_simulationExecuteMaster Orchestration Tool: Executes the complete end-to-end SUMO traffic simulation pipeline in a single call (downloads network, generates routes, opens GUI, and analyzes resul...
-
run_full_triageExecuteRun the full triage pipeline on raw lab report text in one call: parse, classify, route to specialists, and produce a shareable summary.
-
run_gui_simulationExecuteStep 3b: Open the visual SUMO GUI app on your desktop to view vehicles driving on the map in real-time.
-
run_headless_simulationExecuteStep 3: Execute SUMO simulation headlessly using mymap.sumocfg and output stats.xml and tripinfo.xml.
-
run_mutation_cycleExecuteRuns a Safe Test-Driven Mutation Cycle for a detected environmental shift: generates several
-
runWorkflowExecuteTriggers the full end-to-end multi-agent orchestration pipeline
-
scale_deploymentExecuteScale a deployment. SAFETY-ENFORCED: server re-reads the live PDB and policy floor and REJECTS
-
scan_authorization_risksExecuteRuns all detection rules and returns ranked, evidence-backed authorization findings (BOLA, missing auth,
-
secure_check_drug_safetyExecuteRuns pharmacogenomics + drug-interaction analysis through the full Secure Data Gateway pipeline (auth, RBAC, rate limiting, data-minimized AI Gateway routing, audit logging). Re...
-
self_heal_unitExecuteProactively heals a degraded fleet unit by rerouting its operational logic (e.g. falling back
-
set_power_planExecuteSwitches the active Windows power plan.
-
set_process_priorityExecuteChanges the OS scheduling priority of a running process (e.g., set a game to High priority for smoother performance, or a background app to Low so it stops competing for CPU). A...
-
simulate_scenarioExecuteRun counterfactual simulation for candidate maintenance actions
-
simulate_surge_changeExecuteChange live hospital conditions, then recalculate every dashboard and plan. No IDs required.
-
simulate_workflowExecuteRun the full 4-step clinical workflow pipeline.
-
surge_command_centerExecuteRun the complete persistent surge demo: change hospital conditions, compare plans, check policy, approve, execute and inspect the audit trail.
-
test_target_model_v1ExecuteTest the target model v1 (baseline) with an adversarial prompt.
-
test_target_model_v2ExecuteTest the target model v2 (patched) with an adversarial prompt.
-
track_workflowExecuteStart tracking an approved and notified FactoryBrain plan.
-
validate_heuristicExecuteValidates a manufacturing heuristic mathematically against sensor datasets. Exposes the rule and data to the Orchestrator LLM to compute statistical significance.
-
verify_codeExecuteVerify project code
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.