High-risk tools in Octocode MCP - AI Context Platform
301 of the 304 tools in Octocode MCP - AI Context Platform are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
adyenApiKeyExecuteAdyen API key
-
ageSecretKeyExecuteAge encryption secret key
-
ai21ApiKeyExecuteAI21 Labs API key
-
airtablePersonalAccessTokenExecuteAirtable personal access token
-
algoliaApiKeyExecuteAlgolia API key
-
alibabaAccessKeyIdExecuteAlibaba Cloud AccessKey ID
-
amazonBedrockApiKeyExecuteAmazon Bedrock API key
-
anthropicApiKeyExecuteAnthropic API key
-
artifactoryApiKeyExecuteJFrog Artifactory API key
-
asanaPersonalAccessTokenExecuteAsana personal access token
-
assemblyaiApiKeyExecuteAssemblyAI API key
-
atlassianApiTokenExecuteAtlassian API token (Jira/Confluence)
-
auth0ClientSecretExecuteAuth0 client secret
-
auth0ManagementTokenExecuteAuth0 Management API token
-
authressServiceClientAccessKeyExecuteAuthress service client access key
-
awsAccessKeyIdExecuteAWS access key ID
-
awsAccountIdExecuteAWS account ID
-
awsAppSyncApiKeyExecuteAWS AppSync GraphQL API key
-
awsIamRoleArnExecuteAWS IAM role ARN
-
awsLambdaFunctionArnExecuteAWS Lambda function ARN
-
awsMwsAuthTokenExecuteAWS MWS authentication token
-
awsS3BucketArnExecuteAWS S3 bucket ARN
-
awsSecretAccessKeyExecuteAWS secret access key
-
awsSecretsManagerArnExecuteAWS Secrets Manager secret ARN
-
awsSessionTokenExecuteAWS session token
-
azureAdClientSecretExecuteAzure AD client secret
-
azureCosmosDbConnectionStringExecuteAzure Cosmos DB connection string
-
azureOpenaiApiKeyExecuteAzure OpenAI API key
-
azureServiceBusConnectionStringExecuteAzure Service Bus connection string
-
azureStorageConnectionStringExecuteAzure storage account connection string
-
azureSubscriptionIdExecuteAzure subscription ID
-
azureTenantDomainExecuteAzure tenant domain (onmicrosoft.com)
-
base64EncodedSecretsExecuteBase64 encoded secrets in config
-
base64PrivateKeyContentExecuteBase64 encoded private key content
-
basicAuthHeaderExecuteBasic authentication header with credentials
-
binanceApiKeyExecuteBinance API key
-
bitbucketAppPasswordExecuteBitbucket app password
-
bitbucketRepoTokenExecuteBitbucket repository access token
-
bittrexAccessKeyExecuteBittrex access key
-
bugsnagApiKeyExecuteBugsnag API key
-
buildkiteAgentTokenExecuteBuildkite agent token
-
bybitApiKeyExecuteBybit API key
-
cassandraConnectionStringExecuteCassandra connection string with credentials
-
circleciTokenExecuteCircleCI personal API token
-
clerkPublishableKeyExecuteClerk publishable key
-
clerkSecretKeyExecuteClerk secret key
-
clickhouseCloudApiKeyExecuteClickHouse Cloud API secret key
-
clickhouseCredentialsExecuteClickHouse connection string with credentials
-
clojarsApiTokenExecuteClojars API token
-
cloudflareApiKeyExecuteCloudflare API key
-
cloudflareApiTokenPrefixedExecuteCloudflare Access team domain (not API token)
-
cloudflareGlobalApiKeyExecuteCloudflare Global API key
-
cloudflareOriginCaKeyExecuteCloudflare Origin CA key
-
cockroachdbConnectionStringExecuteCockroachDB connection string with credentials
-
codecovAccessTokenExecuteCodecov access token
-
cohereApiKeyExecuteCohere API key
-
coinbaseAccessTokenExecuteCoinbase access token
-
cometApiKeyExecuteComet ML API key
-
contentfulAccessTokenExecuteContentful access token
-
convexDeployKeyExecuteConvex deployment key
-
couchdbCredentialsExecuteCouchDB credentials in URL
-
credentialsInUrlExecuteCredentials embedded in URL
-
customerIoApiKeyExecuteCustomer.io API key
-
databaseUrlWithCredentialsExecuteGeneric database URL with embedded credentials
-
databricksApiTokenExecuteDatabricks API token
-
datadogApiKeyExecuteDatadog API and application keys (with context)
-
deepseekApiKeyExecuteDeepSeek API key
-
denoDeployTokenExecuteDeno Deploy access token
-
depotTokenExecuteDepot.dev build token
-
dhParametersExecuteDiffie-Hellman parameters
-
digitalOceanOAuthTokenExecuteDigitalOcean OAuth access token
-
digitalOceanRefreshTokenExecuteDigitalOcean OAuth refresh token
-
digitalOceanTokenExecuteDigitalOcean API token
-
discordSocialBotTokenExecuteDiscord social bot token
-
discordSocialWebhookUrlExecuteDiscord social webhook URL
-
dockerComposeSecretsExecuteDocker Compose secrets
-
dockerHubTokenExecuteDocker Hub personal access token
-
dopplerApiTokenExecuteDoppler API token
-
dotnetConnectionStringsExecute.NET connection strings with credentials
-
droneCiAccessTokenExecuteDroneCI access token
-
dropboxAccessTokenExecuteDropbox access token
-
dropboxAppKeyExecuteDropbox app key
-
dsaPrivateKeyExecuteDSA private key
-
duffelApiTokenExecuteDuffel travel API token
-
dynatraceApiTokenExecuteDynatrace API token
-
easypostApiTokenExecuteEasyPost API token
-
ecPrivateKeyExecuteElliptic Curve private key
-
elasticsearchCredentialsExecuteElasticsearch credentials in URL
-
elevenLabsApiKeyExecuteElevenLabs API key (context-based detection)
-
envVarSecretsExecuteEnvironment variable secrets (KEY, SECRET, TOKEN, PASSWORD)
-
facebookAccessTokenExecuteFacebook/Meta access token
-
facebookPageAccessTokenExecuteFacebook/Meta page access token
-
faunadbKeyExecuteFaunaDB secret key
-
figmaTokenExecuteFigma personal access token
-
firebaseServiceAccountPrivateKeyExecuteFirebase service account private key (JSON format)
-
fireworksApiKeyExecuteFireworks AI API key
-
flutterwaveKeysExecuteFlutterwave API keys
-
flyioAccessTokenExecuteFly.io API access token
-
flyioMachineTokenExecuteFly.io machine token
-
frameioApiTokenExecuteFrame.io API token
-
freshdeskApiKeyExecuteFreshdesk API key
-
gcpServiceAccountEmailExecuteGCP service account email
-
githubAppInstallationTokenExecuteGitHub App installation token
-
githubFineGrainedTokenExecuteGitHub fine-grained personal access token
-
githubTokensExecuteGitHub personal access token (classic)
-
gitlabCiJobTokenExecuteGitLab CI/CD job token
-
gitlabDeployTokenExecuteGitLab deploy token
-
gitlabFeatureFlagTokenExecuteGitLab feature flag client token
-
gitlabFeedTokenExecuteGitLab feed token
-
gitlabIncomingMailTokenExecuteGitLab incoming mail token
-
gitlabK8sAgentTokenExecuteGitLab Kubernetes agent token
-
gitlabOAuthAppSecretExecuteGitLab OAuth application secret
-
gitlabPersonalAccessTokenExecuteGitLab personal access token
-
gitlabPipelineTriggerTokenExecuteGitLab pipeline trigger token
-
gitlabRunnerTokenExecuteGitLab runner registration token
-
gitlabScimTokenExecuteGitLab SCIM token
-
gitlabSessionCookieExecuteGitLab session cookie
-
gocardlessApiTokenExecuteGoCardless API token
-
googleApiKeyExecuteGoogle API key (GCP, Gemini, Maps, YouTube, etc.)
-
googleOAuth2ClientIdExecuteGoogle OAuth2 client ID
-
googleOAuthClientSecretExecuteGoogle OAuth client secret
-
googleOauthRefreshTokenExecuteGoogle OAuth refresh token
-
googleOauthTokenExecuteGoogle OAuth token
-
grafanaApiKeyExecuteGrafana API key
-
grafanaCloudApiKeyExecuteGrafana Cloud API key
-
grafanaServiceAccountTokenExecuteGrafana service account token
-
grafbaseApiKeyExecuteGrafbase API key
-
groqApiKeyExecuteGroq API key
-
harnessApiKeyExecuteHarness Access Token (PAT or SAT)
-
herokuApiKeyExecuteHeroku API key
-
herokuApiKeyV2ExecuteHeroku API key (new format)
-
hexEncodedKeyExecuteHexadecimal encoded cryptographic key
-
honeycombApiKeyExecuteHoneycomb API key
-
huggingFaceTokenExecuteHugging Face API token
-
infracostApiTokenExecuteInfracost API token
-
instagramAccessTokenExecuteInstagram access token
-
intercomAccessTokenExecuteIntercom access token
-
jdbcConnectionStringWithCredentialsExecuteJDBC connection string with embedded credentials
-
jiraApiTokenExecuteJira API token
-
jsonWebTokenEnhancedExecuteJSON Web Token with enhanced detection
-
jwtSecretsExecuteJWT secrets
-
jwtTokenExecuteJWT (JSON Web Token - 3-part)
-
krakenAccessTokenExecuteKraken access token
-
kubernetesSecretsExecuteKubernetes secrets in YAML
-
kucoinAccessTokenExecuteKucoin access token
-
kucoinSecretKeyExecuteKucoin secret key
-
langchainApiKeyExecuteLangChain/LangSmith API key
-
launchdarklyAccessTokenExecuteLaunchDarkly access token
-
launchdarklySdkKeyExecuteLaunchDarkly SDK key
-
lemonSqueezyApiKeyExecuteLemon Squeezy API key
-
linearApiKeyExecuteLinear API key
-
linkedinApiTokenExecuteLinkedIn API token
-
logdnaApiKeyExecuteLogDNA/Mezmo API key
-
logglyTokenExecuteLoggly customer token
-
mailchimpApiKeyExecuteMailChimp API key
-
mailchimpEcommerceApiKeyExecuteMailChimp E-commerce API key
-
mailgunApiKeyExecuteMailgun API key
-
mapboxPublicTokenExecuteMapbox public access token
-
mapboxSecretTokenExecuteMapbox secret access token
-
mattermostAccessTokenExecuteMattermost access token
-
maxmindLicenseKeyExecuteMaxMind license key
-
messagebirdApiTokenExecuteMessageBird API token
-
microsoftTeamsWebhookExecuteMicrosoft Teams incoming webhook URL
-
mistralApiKeyExecuteMistral AI API key
-
mollieApiKeyExecuteMollie API key
-
mondayApiTokenExecuteMonday.com API token
-
mongodbConnectionStringExecuteMongoDB connection string with credentials (incl. mongodb+srv://)
-
mysqlConnectionStringExecuteMySQL connection string with credentials
-
neo4jCredentialsExecuteNeo4j database credentials in URL
-
neonDatabaseConnectionStringExecuteNeon database connection string
-
netlifyAccessTokenExecuteNetlify access token
-
newRelicApiKeyExecuteNew Relic API key
-
newRelicBrowserApiTokenExecuteNew Relic browser API token
-
newRelicInsertKeyExecuteNew Relic ingest insert key
-
newRelicInsightKeyExecuteNew Relic Insights query key
-
notionIntegrationTokenExecuteNotion integration token (new ntn_ format, post Sept 2024)
-
notionIntegrationTokenLegacyExecuteNotion integration token (legacy secret_ format, pre Sept 2024)
-
novuApiKeyExecuteNovu API key
-
npmAccessTokenExecuteNPM access token
-
nugetApiKeyExecuteNuGet API key
-
nxCloudAccessTokenExecuteNx Cloud access token
-
octopusDeployApiKeyExecuteOctopus Deploy API key
-
oktaAccessTokenExecuteOkta access token
-
onePasswordSecretKeyExecute1Password secret key
-
onePasswordServiceAccountTokenExecute1Password service account token
-
openaiAdminKeyExecuteOpenAI admin API key
-
openaiApiKeyLegacyExecuteOpenAI API key (legacy format)
-
openaiOrgIdExecuteOpenAI organization ID
-
openaiProjectApiKeyExecuteOpenAI project-scoped API key
-
openaiServiceAccountKeyExecuteOpenAI service account API key
-
openshiftUserTokenExecuteOpenShift user token
-
opensshPrivateKeyExecuteOpenSSH private key
-
openvpnClientPrivateKeyExecuteOpenVPN client private key
-
paddleApiKeyExecutePaddle API key
-
paypalAccessTokenExecutePayPal access token
-
paypalBraintreeAccessTokenExecutePayPal Braintree access token
-
perplexityApiKeyExecutePerplexity AI API key
-
pgpPrivateKeyExecutePGP private key block
-
pgpPrivateKeyBlockExecutePGP private key block (BEGIN to END)
-
pineconeApiKeyExecutePinecone API key
-
pineconeApiKeyPrefixedExecutePinecone API key (prefixed format)
-
pinterestAccessTokenExecutePinterest access token
-
pkcs8PrivateKeyExecutePKCS#8 private key
-
plaidApiTokenExecutePlaid API token
-
plaidClientIdExecutePlaid client ID
-
planetScaleConnectionStringExecutePlanetScale connection string
-
planetScaleTokenExecutePlanetScale API token
-
postgresqlConnectionStringExecutePostgreSQL connection string with credentials
-
posthogApiKeyExecutePostHog API key
-
posthogPersonalApiKeyExecutePostHog personal API key
-
postmanApiTokenExecutePostman API token
-
postmarkServerTokenExecutePostmark server API token
-
prefectApiTokenExecutePrefect API token
-
privateKeyPemExecutePrivate key in PEM format (all key types)
-
pulumiAccessTokenExecutePulumi access token
-
pusherAppSecretExecutePusher app secret
-
puttyPrivateKeyExecutePuTTY private key file
-
pypiApiTokenExecutePyPI API token
-
railwayApiTokenExecuteRailway API token
-
razorpayApiKeyExecuteRazorpay API key
-
readmeApiTokenExecuteReadme API token
-
redisAuthPasswordExecuteRedis AUTH password command
-
redisConnectionStringExecuteRedis connection string with credentials (incl. rediss:// TLS)
-
renderTokenExecuteRender API token
-
replicateApiTokenExecuteReplicate API token
-
resendApiKeyExecuteResend email API key
-
rollbarAccessTokenExecuteRollbar access token
-
rsaPrivateKeyExecuteRSA private key
-
rubygemsApiTokenExecuteRubyGems API token
-
scalingoApiTokenExecuteScalingo API token
-
sendbirdAccessTokenExecuteSendbird access token
-
sendgridApiKeyExecuteSendGrid API key
-
sendinblueApiTokenExecuteSendinblue (Brevo) API token
-
sentryAuthTokenExecuteSentry authentication token
-
sentryOrgTokenExecuteSentry organization token
-
sentryUserTokenExecuteSentry user token
-
sessionIdsExecuteSession IDs / Cookies
-
settlemintApplicationAccessTokenExecuteSettleMint application access token
-
settlemintPersonalAccessTokenExecuteSettleMint personal access token
-
settlemintServiceAccessTokenExecuteSettleMint service access token
-
shippoApiTokenExecuteShippo API token
-
shopifyAccessTokenExecuteShopify access token
-
shopifyPrivateAppPasswordExecuteShopify private app password
-
shopifyStorefrontAccessTokenExecuteShopify storefront API access token
-
shopifyWebhookTokenExecuteShopify webhook token
-
slackAppTokenExecuteSlack app-level token
-
slackBotTokenExecuteSlack bot token
-
slackConfigAccessTokenExecuteSlack configuration access token
-
slackRefreshTokenExecuteSlack refresh token
-
slackUserTokenExecuteSlack user token
-
slackWebhookUrlExecuteSlack incoming webhook URL
-
slackWebhookUrlClassicExecuteSlack classic incoming webhook URL
-
slackWorkspaceTokenExecuteSlack workspace token
-
snykApiTokenExecuteSnyk API token
-
sonarqubeTokenExecuteSonarQube/SonarCloud token
-
sourcegraphApiKeyExecuteSourcegraph API key
-
splunkApiTokenExecuteSplunk HEC token
-
squareAccessTokenExecuteSquare access token (all formats)
-
squareApplicationIdExecuteSquare application ID
-
squareOauthSecretExecuteSquare OAuth secret
-
sshPrivateKeyEncryptedExecuteSSH private key (SSH2 encrypted format)
-
stabilityApiKeyExecuteStability AI API key
-
stackhawkApiKeyExecuteStackHawk API key
-
streamApiSecretExecuteStream (GetStream.io) API secret
-
stripePublishableKeyExecuteStripe publishable key (can indicate key pair presence)
-
stripeSecretKeyExecuteStripe secret key - live and test (sk_*, rk_*)
-
stripeWebhookSecretExecuteStripe webhook signing secret
-
sumoLogicAccessIdExecuteSumoLogic access ID
-
supabaseJwtKeyExecuteSupabase anon or service_role key (JWT format)
-
supabaseServiceKeyExecuteSupabase service role key
-
supertokensApiKeyExecuteSuperTokens API key
-
tavilyApiKeyExecuteTavily API key
-
telegramBotTokenExecuteTelegram bot token
-
terraformCloudTokenExecuteTerraform Cloud API token
-
tiktokApiTokenExecuteTikTok API token
-
timescaledbConnectionStringExecuteTimescaleDB connection string with credentials
-
togetherApiKeyExecuteTogether AI API key
-
travisciAccessTokenExecuteTravis CI access token
-
trelloApiKeyExecuteTrello API key
-
triggerDevApiKeyExecuteTrigger.dev API key
-
tursoDatabaseTokenExecuteTurso database auth token
-
twilioAccountSidExecuteTwilio account SID
-
twilioApiKeyExecuteTwilio API key
-
twitterBearerTokenExecuteTwitter/X Bearer token
-
typeformTokenExecuteTypeform API token
-
unstructuredApiKeyExecuteUnstructured.io API key
-
upstashKafkaCredentialsExecuteUpstash Kafka REST credentials
-
upstashRedisTokenExecuteUpstash Redis REST token
-
vaultBatchTokenExecuteHashiCorp Vault batch token
-
vaultPeriodicTokenExecuteHashiCorp Vault periodic token
-
vaultServiceTokenExecuteHashiCorp Vault service token
-
vercelOidcTokenExecuteVercel OIDC token
-
vercelTokenExecuteVercel API token (new prefixed formats: vcp/vci/vca/vcr/vck)
-
vonageApiSecretExecuteVonage/Nexmo API secret
-
voyageApiKeyExecuteVoyage AI API key
-
wandbApiKeyExecuteWeights & Biases API key
-
woocommerceConsumerKeyExecuteWooCommerce consumer key
-
woocommerceConsumerSecretExecuteWooCommerce consumer secret
-
xaiApiKeyExecutexAI (Grok) API key
-
youtubeApiKeyExecuteYouTube Data API key
-
zendeskSecretKeyExecuteZendesk secret key
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.