High-risk tools in Strudel MCP Server
6 of the 10 tools in Strudel MCP Server are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
initExecuteInitialize Strudel in browser
-
transpile_patternExecuteTranspile pattern source via StrudelEngine; returns transpiled code or syntax error
-
validate_pattern_localExecuteValidate pattern syntax against the in-process StrudelEngine (no browser required)
-
validate_pattern_runtimeExecuteValidate pattern with runtime error checking (monitors Strudel console for errors)
-
composeExecuteGenerate, write, and play a complete pattern in one step. Auto-initializes default browser if needed.
-
set_tempoExecuteSet BPM
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.