High-risk tools in Visionmcp
68 of the 376 tools in Visionmcp are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
active_learning.execute_retrainingExecuteQueue the exact training run created by an artifact-bound active-learning plan.
-
active_learning.plan_retrainingExecuteCreate a correction dataset and offline training run against a fixed benchmark.
-
benchmark.bootstrap_calibrationExecuteGenerate, review, and require a verified accepted L3 synthetic calibration project.
-
benchmark.bootstrap_dgx_sparkExecuteBootstrap an unaccepted, measured DGX Spark reconstruction candidate.
-
benchmark.bootstrap_rtx_5090_feExecuteBootstrap an unaccepted, measured RTX 5090 FE reconstruction candidate.
-
benchmark.refine_dgx_spark_base_foot_candidateExecuteQueue a recessed DGX foot refinement without changing the 150 mm body envelope.
-
benchmark.refine_dgx_spark_visual_candidateExecuteQueue a material and rear-I/O DGX candidate while retaining exact body dimensions.
-
benchmark.refine_rtx_5090_fe_front_frame_candidateExecuteQueue an evidence-bound RTX front X-frame refinement at strict dimensions.
-
benchmark.refine_rtx_5090_fe_visual_candidateExecuteQueue a seven-blade RTX visual candidate while retaining strict dimensions.
-
blender.generate_lodExecuteQueue a non-destructive, audited Blender LOD checkpoint for named mesh objects.
-
blender.prepare_assetExecuteQueue bounded retopo, UV, PBR, bake, rig, animation, LOD, collision, and repair.
-
blender.renderExecuteQueue safe headless renders for the current evidence-bound camera solution.
-
camera.derive_undistortedExecuteDerive source-linked pinhole frames while preserving pose and scale authority.
-
campaign.advanceExecuteAdvance exactly one validated OBSERVE-to-ROLLBACK controller state.
-
campaign.resumeExecuteResume a paused campaign at its preserved controller state.
-
campaign.startExecuteStart a persistent evidence-governed reconstruction controller.
-
candidate.evaluate_transactionExecuteEvaluate every mandatory gate atomically and auto-reject any regression.
-
component.generateExecuteQueue allowlisted Blender generation into a new audited checkpoint.
-
coverage.acquire_missingExecuteExecute a bounded governed search for gaps, or issue precise capture requests.
-
dataset.generateExecuteQueue safe headless Blender rendering for a planned synthetic dataset.
-
dataset.train_feature_modelExecutePlan and queue offline feature-model training; no weights are downloaded.
-
evidence.discoverExecuteExecute reviewed search queries and register results with unresolved source rights.
-
geometry.run_ensembleExecuteQueue independent geometry hypotheses followed by license-aware consensus.
-
photogrammetry.runExecuteQueue an evidence-bound photogrammetry lane without promoting unresolved scale.
-
portfolio.execute_initialExecuteExecute cheap local portfolio lanes and record unavailable workers truthfully.
-
portfolio.execute_parametric_seedExecuteBuild a fresh editable dimension-bound seed with no private starting model.
-
recon.bootstrapExecuteQueue the evidence-through-render bootstrap without claiming final fidelity.
-
recon.continue_multiview_searchExecuteQueue or resume isolated render-and-compare evaluation for a planned search.
-
reference.propose_masksExecuteGenerate replayable automatic mask proposals with no review authority.
-
repair.applyExecuteQueue an approved repair, checkpoint audit, topology/ray validation, and rear render.
-
vision.acquire.quarantineExecuteAdvance verified bytes through license, rights, and static scan.
-
vision.app.structureExecuteBuild approximation-only structure, UI-state, and behaviour graphs.
-
vision.benchmark_targetExecuteRun the owned application benchmark; external gates report blocked rather than pass.
-
vision.binary.analyzeExecuteRun one bounded headless Ghidra analysis in an isolated worker process.
-
vision.build_industrial_modelExecuteBuild an editable unbranded industrial-design hierarchy with geometric residual authority.
-
vision.build_reconstruction_portfolioExecuteRun requested reconstruction backends and seal a ReconstructionPortfolio.
-
vision.compileExecuteCompile observed layout/text/paint evidence into deterministic HTML/CSS.
-
vision.compile_cinematic_sceneExecuteExport browser motion table from a CameraPathGraph; optional Blender bake is honest.
-
vision.compile_motionExecuteCompile MotionGraph into reusable sticky, scroll, reveal, media, camera, and responsive primitives.
-
vision.evaluateExecuteRun a capsule evaluation or mandatory global frontend non-regression gate.
-
vision.fit_parametric_modelExecuteFit a RANSAC plane/box/cylinder/sphere; result authority is MODEL_DERIVED.
-
vision.generate_furExecuteGroom fur in Blender; returns measured groom report or an explicit blocked state.
-
vision.generate_lodsExecuteGenerate measured LODs; report blender_used=false when Blender is blocked.
-
vision.generate_texture_setExecuteGenerate tileable PBR maps from a MaterialHypothesis (not observed textures).
-
vision.generate_uvsExecuteGenerate UVs in Blender; return measured quality or a blocked state.
-
vision.generate.authorizedExecuteGenerate after verified search exhaustion or an explicit original declaration.
-
vision.measure_visual_parityExecuteRun governed pixel, perceptual, layout, typography, crop, stacking, and distribution metrics.
-
vision.retopologizeExecuteRetopologize via real Blender; blocked state is reported if Blender cannot run.
-
vision.runExecuteQueue normalized geometry evidence generation without promoting unresolved scale.
-
vision.run_perceptual_criticsExecuteRun specialist critics and seal a PerceptualCritique with measured findings.
-
vision.saccadeExecutePlan and commit a saccade to a new region (IOR-aware).
-
vision.solve_calibration_boardExecuteRecover metric OpenCV cameras from an authoritative measured chessboard.
-
vision.solve_camerasExecuteQueue camera solving while preserving backend authority and uncertainty labels.
-
vision.solve_lightingExecuteSolve a LightingHypothesisSet capped by derive() over inputs.
-
vision.solve_product_cameraExecuteSolve an evidence-bound product camera from six or more 3D/2D landmarks.
-
vision.trackExecuteAssociate detections to tracks for one frame (IoU + appearance + Kalman).
-
vision.transplant_featureExecuteCompile and verify a clean-room behavior capsule without copying source assets.
-
visual_oracle.trainExecutePlan and queue camera-bound offline appearance-oracle training.
-
worker.failExecuteReport a structured failure and retry up to the job's configured attempt limit.
-
workflow.audit_reference_fidelityExecuteRun the first complete audit slice asynchronously from evidence through receipt.
-
workflow.continue_autonomousExecuteExecute the next safe evidence-derived action or stop at an authority boundary.
-
workflow.fit_componentExecuteQueue a robust fit proposal; named review is required before parameters change.
-
workflow.generate_original_assetExecuteLaunch an explicitly L0 generated-design portfolio without measured-target claims.
-
workflow.reconstruct_hardwareExecuteLaunch the computer-hardware ontology and reconstruction portfolio.
-
workflow.reconstruct_organic_subjectExecuteLaunch anatomical landmarks and distinguish real reconstruction from generation.
-
workflow.reconstruct_packagingExecuteLaunch packaging folds, layers, print regions, and reconstruction hypotheses.
-
workflow.reconstruct_productExecuteQueue the complete staged reconstruction/audit workflow and retain all blockers.
-
workflow.reconstruct_vehicleExecuteLaunch the vehicle ontology, constraints, search plan, and candidate portfolio.
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.