High-risk tools in Jules MCP Server
4 of the 11 tools in Jules MCP Server are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
create_coding_taskExecuteCreates a new Jules coding session. Returns immediately with a session ID. Monitor progress via jules://sessions/{id}/full resource.
-
create_repoless_taskExecuteCreates a new Jules session without repository context for scripts, prototypes, or research tasks.
-
manage_sessionExecuteManage an active Jules session: approve or reject plans, or send feedback
-
schedule_recurring_taskExecuteSchedule a Jules task to run automatically on a cron schedule. The server manages execution even when offline.
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.