High-risk tools in MCP SSH Orchestrator
6 of the 13 tools in MCP SSH Orchestrator are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
ssh_cancelExecuteRequest cancellation for a running task.
-
ssh_cancel_async_taskExecuteCancel a running async task.
-
ssh_runExecuteExecute SSH command with policy, network checks, progress, timeout, and cancellation.
-
ssh_run_asyncExecuteStart SSH command asynchronously (SEP-1686 compliant).
-
ssh_run_on_tagExecuteExecute SSH command on all hosts with a tag (with network checks).
-
ssh_reload_configExecuteReload configuration files.
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.