High-risk tools in PMCP
7 of the 26 tools in PMCP are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
gateway.tasks_cancelExecuteCancel a downstream MCP task by opaque task ID.
-
gateway.connect_serverExecuteConnect or start a known downstream MCP server by name.
-
gateway.invokeExecuteInvoke a tool on a downstream MCP server.
-
gateway.provisionExecuteProvision (install and start) a specific MCP server from the manifest.
-
gateway.restart_serverExecuteRestart a known downstream MCP server without changing persistent config.
-
gateway.refreshExecuteReload backend MCP server configurations and reconnect.
-
gateway.request_capabilityExecuteFind and auto-provision the right tool for a task — describe what you need in natural language.
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.