DESTRUCTIVE MCP TOOLS
Tools that permanently delete or destroy resources. Critical risk -- block by default.
Severity: Critical severity →
Real-world attack patterns documented against destructive-class MCP tools. Each links to the full case and the defensive policy.
delete_appointment Delete an appointment delete_contact Delete a contact from GoHighLevel delete_contact_note Delete a note from a contact delete_contact_task Delete a task from a contact delete_custom_field Delete a custom field delete_custom_value Delete a custom value delete_opportunity Delete an opportunity from GoHighLevel delete_user Delete a user remove_contact_from_workflow Remove a contact from a workflow bulk_delete_social_posts Delete multiple social media posts at once (max 50) cancel_scheduled_campaign_message Cancel a scheduled campaign message for a contact cancel_scheduled_email Cancel a scheduled email before it is sent + 405 more Every GoHighLevel MCP Server tool, risk-classified, on the server page. pfsense_delete_auth_key pfsense_delete_auth_key pfsense_delete_auth_keys pfsense_delete_auth_keys pfsense_delete_diagnostics_arp_table pfsense_delete_diagnostics_arp_table pfsense_delete_diagnostics_arp_table_entry DELETE /api/v2/diagnostics/arp_table/entry pfsense_delete_diagnostics_config_history_revision DELETE /api/v2/diagnostics/config_history/revision pfsense_delete_diagnostics_config_history_revisions pfsense_delete_diagnostics_config_history_revisions pfsense_delete_diagnostics_table DELETE /api/v2/diagnostics/table pfsense_delete_firewall_alias DELETE /api/v2/firewall/alias pfsense_delete_firewall_aliases pfsense_delete_firewall_aliases pfsense_delete_firewall_nat_one_to_one_mapping pfsense_delete_firewall_nat_one_to_one_mapping pfsense_delete_firewall_nat_one_to_one_mappings pfsense_delete_firewall_nat_one_to_one_mappings pfsense_delete_firewall_nat_outbound_mapping pfsense_delete_firewall_nat_outbound_mapping + 166 more Every Pfsense tool, risk-classified, on the server page. dedup_planner_todos Remove duplicate Planner ToDo items that the Huly server sometimes creates more than once per issue delete_attachment Permanently delete an attachment. This action cannot be undone. delete_card Permanently delete a Huly card. This action cannot be undone. delete_channel Permanently delete a Huly channel. This action cannot be undone. delete_channel_message Permanently delete a channel message. This action cannot be undone. delete_comment Delete a comment from a Huly issue. This action cannot be undone. delete_component Permanently delete a Huly component. This action cannot be undone. delete_dm_message Permanently delete a direct-message message. The delete_document Permanently delete a Huly document. This action cannot be undone. delete_event Permanently delete a calendar event. This action cannot be undone. delete_issue Permanently delete a Huly issue. This action cannot be undone. delete_issue_template Permanently delete a Huly issue template. This action cannot be undone. + 119 more Every Huly tool, risk-classified, on the server page. delete_site Permanently delete an owned site. Irreversible — confirm with the user first. delete_variable Delete an account variable. drive_delete_file Delete one file from a drive. drive_revoke_token Revoke a drive share token. delete_address_rule Delete an allow/block rule. delete_inbox Delete an inbox. Mail to its address stops being accepted. delete_webhook Delete a webhook endpoint. htmldrop_delete Delete a site by its id. The id is the opaque string returned from htmldrop_list (NOT the slug). Once deleted the public URL returns 404 immediately. delete_topic Soft-delete a topic (creator only). revoke_invite Revoke/delete an invite (creator only). swiftsign_void_envelope Cancel/void an envelope that hasn't been completed yet. Signers can no longer sign a voided envelope. Works in both sandbox (sk_test_ keys) and live. delete_backup Deletes a backup by ID. + 116 more Every Mcp tool, risk-classified, on the server page. discord_ban_member Ban a member from a guild (requires confirm=true) discord_begin_guild_prune Begin guild prune (requires confirm=true) discord_bulk_ban_members Bulk ban members in a guild (requires confirm=true) discord_clear_emoji_reactions Clear all reactions for a specific emoji from a message discord_clear_reactions Clear all reactions from a message discord_delete_application_emoji Delete an application emoji (requires confirm=true) discord_delete_automod_rule Delete an auto moderation rule (requires confirm=true) discord_delete_channel Delete a channel (requires confirm=true) discord_delete_channel_permission_overwrite Delete a channel permission overwrite (requires confirm=true) discord_delete_guild_emoji Delete a guild emoji (requires confirm=true) discord_delete_guild_soundboard_sound Delete a guild soundboard sound (requires confirm=true) discord_delete_guild_sticker Delete a guild sticker (requires confirm=true) + 112 more Every Discord tool, risk-classified, on the server page. archive_advertiser Archive an advertiser (soft-delete, can be restored later) archive_channel Archive a channel (soft-delete, can be restored later) archive_contract Archive a contract (soft-delete, can be restored later) archive_email_zone Archive an email zone archive_publisher Archive a publisher (soft-delete, can be restored later) bulk_upload_remove_data_list Bulk remove entries from a data list bulk_upload_replace_user_db Bulk upload to replace all user data in a user database campaign_bulk_delete_catalog_ad_items Bulk delete catalog ad items from a campaign cancel_signature_request Cancel a signature request delete_advertiser Delete an advertiser delete_archived_campaign Permanently delete an archived standard campaign delete_archived_channel Permanently delete an archived channel + 101 more Every AdButler tool, risk-classified, on the server page. marchward_authorize Check whether an action is allowed BEFORE the agent takes it. Call this first for any consequential or irreversible action (deploying, committing, ... delete_standing_intent Permanently retire a registered standing intent (webhook watch) by intent_id — deliveries stop and the watch cannot be recovered. Requires a key. G... cancel_order [orders-admin] Cancel an order (status → canceled). Optional reason stored as order comment. clear_app_cache [settings] Clear application cache for a specific installation. DELETE /clearAppCache/{installation_key}. Requires admin/write scope. delete_attribute [attributes] Delete an attribute definition by id. delete_attribute_group [attributes] Delete an attribute group by id. delete_attribute_value [attributes] Delete an attribute value by id. delete_billing_address [b2b] Delete a billing address by ID. delete_brand [catalog] Delete a brand (attribute value). Fails with 409 if products still use it unless force=true. delete_category [catalog] Delete a category by ID. May fail if products are still assigned. delete_company [customer] Delete a company by ID. CustomerHub DELETE /companies/{id}. delete_customer [b2b] Delete a customer by ID. + 82 more Every Mcp Server tool, risk-classified, on the server page. admin_delete_app_password Löscht ein Application Password admin_delete_user Löscht einen WordPress-Benutzer (erfordert Reassign) comment_delete Löscht einen Kommentar image_delete_unused Löscht Bilder die nicht verwendet werden (VORSICHT!) revision_cleanup Löscht alte Revisionen und behält nur die letzten N Versionen revision_delete Löscht eine spezifische Revision woo_delete_product Löscht ein WooCommerce Produkt wp_delete_post Löscht einen WordPress-Beitrag (verschiebt in Papierkorb oder endgültig) wp_delete_post Delete a WordPress post. delete_post Trash or permanently delete a WordPress post. By default moves to trash. Use force=true for permanent deletion (irreversible). delete_comment Deletes a comment delete_content Deletes content of any type + 69 more Every WordPress MCP Server tool, risk-classified, on the server page. chaoxing_cancel_personal_group_export Preview or confirm cancelling and removing a personal group export job. chaoxing_clear_personal_group_external_members Preview or confirm removing every non-Chaoxing member from one personal group. chaoxing_clear_study_monitor_anomaly Preview or confirm clearing one student's removable study-anomaly record. chaoxing_delete_ai_command Preview or confirm deleting a custom command or removing a mapped command. chaoxing_delete_ai_command_group Preview or confirm deleting a custom AI command group. chaoxing_delete_chapter_card Preview or confirm permanent deletion of one chapter page. chaoxing_delete_chapters Preview or confirm permanent deletion of chapters and all descendant content. chaoxing_delete_class Preview or confirm deleting one course class. chaoxing_delete_class_activity Preview or confirm moving a class activity to recycle. chaoxing_delete_class_activity_group Preview or confirm deleting a custom activity group. chaoxing_delete_cloud_disk_items Preview or confirm removal of owned items from the active cloud-disk list. chaoxing_delete_contact_team Preview or confirm deleting a custom address-book team. + 68 more Every Chaoxing Agent tool, risk-classified, on the server page. delete_category Delete a specific category. delete_comment Delete a comment from a recipe. delete_cookbook Delete a specific cookbook. This does not delete the recipes in the cookbook. delete_food Delete a specific food. delete_label Delete a specific label. delete_mealplan Delete a mealplan entry. delete_recipe Delete a recipe permanently. delete_shopping_list Delete a specific shopping list. delete_shopping_list_item Delete a specific shopping list item. delete_shopping_list_items_bulk Delete multiple shopping list items at once. delete_tag Delete a specific tag. delete_tool Delete a specific recipe tool. + 67 more Every Mealie MCP Server tool, risk-classified, on the server page. cancel_host_maintenance Cancel host maintenance mode delete_account Delete a CloudStack account delete_account_from_project Remove an account from a project delete_alerts Delete system alerts delete_application_load_balancer Delete application load balancer delete_bgp_peer Delete BGP peer delete_customer_gateway Delete a customer gateway delete_dhcp_option Delete a DHCP option delete_disk_offering Delete disk offering delete_domain Delete a domain delete_egress_firewall_rule Delete an egress firewall rule delete_firewall_rule Delete firewall rule + 66 more Every CloudStack MCP Server tool, risk-classified, on the server page. delete_access_token delete_access_token delete_asset delete_asset delete_asset_folder delete_asset_folder delete_branch delete_branch delete_component delete_component delete_component_folder delete_component_folder delete_datasource delete_datasource delete_datasource_entry delete_datasource_entry delete_preset delete_preset delete_release delete_release delete_space delete_space delete_space_role delete_space_role + 61 more Every Storyblok MCP Server tool, risk-classified, on the server page. delete_credential delete_credential delete_execution Hapus rekaman eksekusi dari n8n secara permanen. delete_tag Hapus tag dari n8n. delete_variable Hapus variable dari n8n secara permanen. delete_workflow Hapus workflow dari n8n secara permanen. n8n_delete_credential Delete a credential.
⚠️ WARNING: This will break any workflows using this credential!
Args:
- id (string): Credential ID to delete
Returns:
... n8n_delete_execution Delete a specific execution by ID.
⚠️ WARNING: This action cannot be undone!
Args:
- id (string): Execution ID to delete
Returns:
Confirmati... n8n_delete_executions Delete multiple executions based on filters.
⚠️ WARNING: This action cannot be undone! Use with caution.
Args:
- workflowId (string, optional):... n8n_delete_project Delete a project.
⚠️ WARNING: All workflows and credentials in this project will be affected!
Args:
- id (string): Project ID to delete
Return... n8n_delete_tag Delete a tag.
Args:
- id (string): Tag ID to delete
Returns:
Confirmation of deletion. n8n_delete_variable Delete a variable.
⚠️ WARNING: Workflows using this variable will break!
Args:
- id (string): Variable ID to delete
Returns:
Confirmation of... n8n_delete_workflow Permanently delete a workflow.
⚠️ WARNING: This action cannot be undone!
Args:
- id (string): Workflow ID to delete
Returns:
Confirmation of... + 51 more Every n8n MCP Server tool, risk-classified, on the server page. hubspot_delete_association Remove an association between two HubSpot objects. hubspot_delete_call Archive (soft delete) a call engagement in HubSpot. hubspot_delete_company Archive (soft delete) a company in HubSpot. hubspot_delete_contact Archive (soft delete) a contact in HubSpot. hubspot_delete_deal Archive (soft delete) a deal in HubSpot. hubspot_delete_email_engagement Archive (soft delete) an email engagement in HubSpot. hubspot_delete_meeting Archive (soft delete) a meeting engagement in HubSpot. hubspot_delete_note Archive (soft delete) a note in HubSpot. hubspot_delete_task Archive (soft delete) a task in HubSpot. hubspot_delete_ticket Archive (soft delete) a ticket in HubSpot. calls_archive Archive (delete) a call record calls_batch_archive Archive (delete) multiple call records in a single request + 50 more Every HubSpot MCP Server tool, risk-classified, on the server page. mikrotik_clear_address_list Removes all entries from a specific address list (⚠️ destructive!) mikrotik_clear_logs Clears all logs from MikroTik device mikrotik_delete_custom_chain Delete a custom chain and all its rules (⚠️ destructive!) mikrotik_remove_address_list_entry Removes an entry from a firewall address list mikrotik_remove_bonding_interface Remove bonding interface mikrotik_remove_bridge_port Removes an interface from its bridge mikrotik_remove_bridge_vlan Removes VLAN configuration from a bridge mikrotik_remove_capsman_configuration Removes a CAPsMAN configuration profile mikrotik_remove_capsman_datapath Removes a CAPsMAN datapath configuration mikrotik_remove_capsman_provisioning_rule Removes a CAPsMAN provisioning rule mikrotik_remove_certificate Removes a certificate from the device mikrotik_remove_container Removes a container + 48 more Every MikroTik Cursor MCP tool, risk-classified, on the server page. delete_work_item Delete a work item. archive_cycle Archive a cycle. delete_cycle Delete a cycle by ID. delete_epic Delete an epic by ID. delete_initiative Delete an initiative by ID. delete_intake_work_item delete_intake_work_item delete_label Delete a label by ID. delete_milestone Delete a milestone by ID. delete_module Delete a module by ID. delete_project Delete a project by ID. delete_state Delete a state by ID. delete_work_item Delete a work item by ID. + 47 more Every Plane tool, risk-classified, on the server page. delete_instance delete_instance cancel_account Cancel your account cancel_backups Cancel backups for a Linode instance cancel_object_storage Cancel Object Storage service delete_alert_definition Delete an alert definition delete_api_token Delete an API token delete_config_interface Delete an interface from a configuration profile delete_domain Delete a domain delete_domain_record Delete a domain record delete_firewall Delete a firewall delete_firewall_device Delete a device from a specific firewall delete_image Delete an Image + 46 more Every Linode MCP Server tool, risk-classified, on the server page. terminate_cluster Terminate a Databricks cluster with parameter: cluster_id (string, required) databricks_dbfs_delete databricks_dbfs_delete databricks_delete_app databricks_delete_app databricks_delete_catalog databricks_delete_catalog databricks_delete_connection databricks_delete_connection databricks_delete_database_instance databricks_delete_database_instance databricks_delete_experiment databricks_delete_experiment databricks_delete_external_location databricks_delete_external_location databricks_delete_function databricks_delete_function databricks_delete_git_credential databricks_delete_git_credential databricks_delete_global_init_script databricks_delete_global_init_script databricks_delete_group databricks_delete_group + 45 more Every Databricks MCP Server tool, risk-classified, on the server page. gcp_agent_delete_app Delete an Agent Builder application gcp_agent_delete_data_store Delete a data store gcp_agent_delete_endpoint Delete a Vertex AI endpoint gcp_agent_delete_model Delete a Vertex AI model gcp_agent_delete_reasoning_engine Delete a Reasoning Engine gcp_appengine_delete_service Delete an App Engine service gcp_appengine_delete_version Delete an App Engine version gcp_ar_delete_package Delete a package from a repository gcp_ar_delete_repository Delete an Artifact Registry repository gcp_ar_delete_version Delete a package version gcp_bq_delete_dataset Delete a BigQuery dataset gcp_bq_delete_table Delete a BigQuery table + 43 more Every GCP MCP Server tool, risk-classified, on the server page. agency-hosting_clearWebsiteCacheV1 Clears cache for all domains associated with an Agency Plan website, including its preview domain.
This operation clears all cache types for the w... agency-hosting_deleteWebsiteCronJobV1 Permanently deletes the cron job identified by its uuid from an Agency Plan website.
The operation is idempotent: deleting a cron job that does no... agency-hosting_deleteWebsiteDatabaseUserV1 Permanently deletes a database user from an Agency Plan website database, revoking all access it had.
The operation is idempotent: deleting a user... agency-hosting_deleteWebsiteDatabaseV1 Permanently deletes a MySQL database and all its data from an Agency Plan website, including its users.
The operation is idempotent: deleting a da... agency-hosting_deleteWebsiteV1 Permanently deletes an Agency Plan website. Deletion is processed asynchronously: the
website is immediately transitioned to a deleting state and t... agency-hosting_deployNodeStaticWebsite Deploy a node-static Agency Plan (h5g) website from an archive file. WARNING: this overwrites the website's existing contents and cannot be undone ... agency-hosting_deployPhpApplication Deploy a PHP (or other non-build) Agency Plan (h5g) website from an archive file. WARNING: this overwrites the website's existing contents and cann... billing_deletePaymentMethodV1 Delete a payment method from your account.
Use this endpoint to remove unused payment methods from user accounts. DNS_deleteDNSRecordsV1 Delete DNS records for the selected domain.
To filter which records to delete, add the `name` of the record and `type` to the filter.
Multiple fi... DNS_resetDNSRecordsV1 Reset DNS zone to the default records.
Use this endpoint to restore domain DNS to original configuration. domains_cancelPendingIRTPVerificationV1 Cancel a pending IRTP verification.
Use this endpoint to back out of a WHOIS change that is stuck waiting on registrant confirmation,
for example ... domains_deleteDomainForwardingV1 Delete domain forwarding data.
Use this endpoint to remove redirect configuration from domains. + 43 more Every Hostinger Api tool, risk-classified, on the server page. cancel_order Cancel a specific order. binance_us_cancel_all_open_orders Cancel all active orders on a symbol on Binance.US. This includes OCO orders. Use with caution - this will cancel ALL open orders for the specified... binance_us_cancel_oco Cancel an entire OCO order on Binance.US. Cancelling any individual leg will cancel the entire OCO. binance_us_cancel_order Cancel an active order on Binance.US. Either orderId or origClientOrderId must be provided. binance_us_cancel_replace Cancel an existing order and place a new order on the same symbol atomically. This is useful for modifying order parameters. binance_us_cust_cancel_oco Cancel an entire OCO (One-Cancels-the-Other) order list.
⚠️ REQUIRES CUSTODIAL SOLUTION API KEY
This cancels both legs of the OCO order.
Respons... binance_us_cust_cancel_order Cancel an active custodial trade order.
⚠️ REQUIRES CUSTODIAL SOLUTION API KEY
Either orderId or origClientOrderId must be provided.
Response in... binance_us_cust_cancel_orders_symbol Cancel all active custodial orders for a specific trading pair.
⚠️ REQUIRES CUSTODIAL SOLUTION API KEY
This includes OCO orders. Use with caution... BinanceCancelHashRateResaleConfiguration Cancel an existing hashrate resale configuration using the mining ID and account details. BinanceConvertCancelLimitOrder Cancels a previously placed limit order using the orderId and returns the cancellation status along with the orderId. BinanceCrossMarginCancelAllOrders Cancel all open margin orders for a specific trading pair. This will cancel all open orders on the symbol. BinanceCrossMarginCancelOrder Cancel an active margin order. Either orderId or origClientOrderId must be provided. + 42 more Every Binance MCP Server tool, risk-classified, on the server page. delete_checklist Delete a checklist (and all its items) from a card archive_list Send a list to the archive on a specific board delete_checklist_item Delete a checklist item from a card delete_comment Delete a comment from a Trello card delete_label Delete a label from a board delete_attachment Delete an attachment from a Trello card. delete_board Delete a Trello board permanently. This action cannot be undone. delete_card Delete a Trello card permanently. This action cannot be undone. To hide a card while preserving it, use archive_card instead. delete_check_item Delete a check item from a checklist. delete_checklist Delete a Trello checklist permanently. delete_comment Delete a Trello comment permanently. delete_label Delete a Trello label permanently. + 41 more Every Trello tool, risk-classified, on the server page. pipedrive_convert_deal_to_lead Convert a deal to a lead (async job). DESTRUCTIVE: a successful conversion marks the source deal as deleted. Returns a conversion_id; the conversio... pipedrive_convert_lead_to_deal Convert a lead into a deal (Pipedrive v2). DESTRUCTIVE: a successful conversion marks the source lead as deleted. The conversion runs asynchronousl... pipedrive_delete_activity Delete an activity. pipedrive_delete_board Delete a project board. Requires PIPEDRIVE_MODE=full (back-compat: PIPEDRIVE_ENABLE_DESTRUCTIVE=true). (Projects add-on; Projects API in public beta.) pipedrive_delete_deal Delete a deal. The deal will be marked as deleted and permanently removed after 30 days. pipedrive_delete_deal_discount Delete an additional discount from a deal. pipedrive_delete_deal_field Delete a deal custom field by field_code. Requires PIPEDRIVE_MODE=full (back-compat: PIPEDRIVE_ENABLE_DESTRUCTIVE=true). pipedrive_delete_deal_field_options Bulk-delete options of a deal enum/set field. Atomic: fails if any ID does not exist. Requires PIPEDRIVE_MODE=full (back-compat: PIPEDRIVE_ENABLE_D... pipedrive_delete_deal_follower Remove a follower from a deal. pipedrive_delete_deal_installment Delete an installment from a deal. Growth+ plan required. pipedrive_delete_deal_product Remove a line-item product from a deal. pipedrive_delete_lead Delete a lead. Requires PIPEDRIVE_MODE=full (back-compat: PIPEDRIVE_ENABLE_DESTRUCTIVE=true). + 41 more Every Pipedrive MCP Server tool, risk-classified, on the server page. marketo_delete_channel Delete a channel by ID. Fails if any programs are currently using this channel. marketo_delete_lead Permanently delete a lead by its numeric ID. This action cannot be undone. custom_cancel_lead_export_job [CUSTOM] Calls the Marketo REST API directly (not Adobe's native MCP). custom_delete_companies [CUSTOM] Calls the Marketo REST API directly (not Adobe's native MCP). custom_delete_custom_activity_type [CUSTOM] Calls the Marketo REST API directly (not Adobe's native MCP). custom_delete_custom_activity_type_attributes [CUSTOM] Calls the Marketo REST API directly (not Adobe's native MCP). custom_delete_custom_object_type [CUSTOM] Calls the Marketo REST API directly (not Adobe's native MCP). custom_delete_custom_object_type_fields [CUSTOM] Calls the Marketo REST API directly (not Adobe's native MCP). custom_delete_custom_objects [CUSTOM] Calls the Marketo REST API directly (not Adobe's native MCP). custom_delete_email [CUSTOM] Calls the Marketo REST API directly (not Adobe's native MCP). custom_delete_email_module [CUSTOM] Calls the Marketo REST API directly (not Adobe's native MCP). custom_delete_email_template [CUSTOM] Calls the Marketo REST API directly (not Adobe's native MCP). + 40 more Every Marketo MCP Server tool, risk-classified, on the server page. calls_archive Archive (delete) a call record calls_batch_archive Archive (delete) multiple call records in a single request crm_batch_delete_associations Delete multiple associations in a single request crm_batch_delete_objects Delete multiple CRM objects in a single request crm_delete_association Delete an association between two objects crm_delete_object Delete a CRM object emails_archive Archive (delete) an email record emails_batch_archive Archive (delete) multiple email records in a single request engagement_details_delete Delete an engagement meetings_batch_archive Archive (delete) multiple meetings in a single request meetings_delete Delete a meeting notes_archive Archive (delete) a note + 39 more Every HubSpot MCP tool, risk-classified, on the server page. delete_few_records Видалити декілька записів одним запитом delete_field Delete a field (column, property) from a form. Irreversible — all data in this field will be lost. (remove field, drop column) delete_form Видалити форму та всі її записи. Незворотна операція. Не можна видалити єдину форму. delete_portal_group Видалити групу порталу разом з правами і учасниками. delete_portal_menu_item Видалити пункт меню порталу. section_id для top-level, item_id для підпункту підменю. delete_portal_user Видалити юзера з порталу delete_project Видалити проєкт (ставить hidden=true і запускає фоновий DeleteAppJob). delete_record Видалити запис delete_records_by_filter Масове видалення записів за фільтром, переліком ID або всіх записів форми. Незворотна операція. delete_reminder Видалити нагадування. delete_saved_view Видалити збережений набір фільтрів пошуку. delete_schedule Видалити розклад. + 39 more Every QuintaDB tool, risk-classified, on the server page. delete_from_alias Delete an entry from a firewall alias firewall_delete_rule Delete a firewall rule by UUID clear_logs clear_logs delete_acme_account Delete an ACME (Let delete_acme_certificate Delete an ACME (Let delete_bridge_interface Delete a bridge interface delete_certificate Delete a certificate delete_certificate_authority Delete a Certificate Authority delete_certificate_signing_request Delete a Certificate Signing Request delete_from_alias Delete an entry from a firewall alias delete_group Delete a group delete_lagg_interface Delete a LAGG interface + 38 more Every OPNsense MCP Server tool, risk-classified, on the server page. bulk_delete_security_profile_entries bulk_delete_security_profile_entries clear_database_cache clear_database_cache delete_adom_revision delete_adom_revision delete_central_dnat_policy Delete a central DNAT policy. delete_central_snat_policy Delete a central SNAT policy. delete_certificate_template delete_certificate_template delete_cli_script delete_cli_script delete_cli_template Delete a CLI template. delete_cli_template_group Delete a CLI template group. delete_custom_application Delete a custom application. delete_device_blueprint Delete a device blueprint. delete_device_group Delete a device group. + 38 more Every Fortimanager tool, risk-classified, on the server page. altegio_delete_appointment altegio_delete_appointment altegio_delete_client altegio_delete_client altegio_delete_staff altegio_delete_staff altegio_delete_transaction altegio_delete_transaction amocrm_delete_custom_field amocrm_delete_custom_field amocrm_delete_note amocrm_delete_note amocrm_delete_pipeline Delete a pipeline (only if empty — AmoCRM rejects deletes with leads). amocrm_delete_status amocrm_delete_status binotel_delete_customers binotel_delete_customers google_ads_delete_campaign google_ads_delete_campaign google_sheets_clear_basic_filter google_sheets_clear_basic_filter google_sheets_clear_formatting google_sheets_clear_formatting + 36 more Every Allmcp tool, risk-classified, on the server page. caddy_remove_site Remove a site block from the Caddyfile (matched by address) and reload Caddy. Destructive — the change is persisted to disk. crow_bookstack_delete Delete a page or chapter from BookStack (irreversible) crow_campaign_delete Delete a campaign and all its posts. Requires confirmation. crow_data_write Execute a write SQL statement (INSERT, CREATE TABLE, UPDATE, DELETE) on a user-owned database. Separate from read-only queries for safety. crow_deactivate_server Deactivate a server crow_delete_bot_schedule Delete a recurring bot-cron schedule by its scheduleId (from crow_list_bot_schedules). crow_delete_context_section Delete a custom crow.md section. Protected sections cannot be deleted — only disabled. Scoped overrides (device/project) of protected sections CAN ... crow_delete_file Permanently delete a file from storage. This cannot be undone. Returns a preview and confirmation token on first call; pass the token back to execute. crow_delete_memory Permanently delete a memory. This cannot be undone. Returns a preview and confirmation token on first call; pass the token back to execute. crow_delete_post Permanently delete a blog post. This cannot be undone — use crow_unpublish_post to revert to draft instead. Returns a preview and confirmation toke... crow_delete_setlist Permanently delete a setlist. Returns a preview and confirmation token on first call; pass the token back to execute. crow_frigate_set_detect Enable/disable motion detection for a camera. DESTRUCTIVE: disabling detect also stops motion-triggered recording on that camera. Use sparingly. + 36 more Every Crow tool, risk-classified, on the server page. todoist_delete_task Delete a task from Todoist by searching for it by name delete_project Delete a project delete_task Delete a task delete_task Delete a task. delete_comment Delete a comment delete_label Delete a label delete_project Delete a Todoist project delete_section Delete a Todoist section delete_task Delete a TODO task todoist_delete_personal_label Delete a personal label from Todoist todoist_delete_task Delete one or more tasks from Todoist todoist_delete_personal_label Delete a personal label from Todoist + 35 more Every Todoist MCP Server tool, risk-classified, on the server page. theprotocol_agentRevokeAttestation Self-revoke one of your agent's attestations (Phase 2). Optional reason. Requires agent JWT. theprotocol_authForgotPassword DESTRUCTIVE: request password reset email. Public. theprotocol_authResetPassword DESTRUCTIVE: reset password via emailed token. Public. theprotocol_authSetNewPassword DESTRUCTIVE: set new password after recovery flow. Public. theprotocol_cancelExchangeOrder AGORA: cancel my open order. Requires agent JWT. theprotocol_changePassword DESTRUCTIVE: change account password. theprotocol_createTegPolicy DESTRUCTIVE: create a TEG policy. Requires admin_treasury flag. theprotocol_crossRegistryContractProxy DESTRUCTIVE: proxy contract action to another registry. Agent JWT. theprotocol_deleteBundle DESTRUCTIVE: delete one of your bundles. Owner-only. theprotocol_deleteFederationPeerSelf DESTRUCTIVE: delete a federation peer registration (own peer). theprotocol_deleteMyAgent DESTRUCTIVE: delete the calling agent (self-delete via /agents/me). theprotocol_deleteMyAgentByDev HIGHLY DESTRUCTIVE: delete one of your agents from dev account. + 35 more Every TheProtocol — Sovereign AI Agent Platform tool, risk-classified, on the server page. create-document-version-rollback Rollback document to a specific version delete-data-type Deletes a data type by Id delete-data-type-folder Deletes a data type folder by Id delete-dictionary-item Deletes a dictionary item by Id delete-document Deletes a document by Id delete-document-blueprint Deletes a document blueprint by Id delete-document-blueprint-folder Deletes a document blueprint folder by Id delete-document-public-access Removes public access settings from a document by Id. delete-document-recycle-bin-item Permanently deletes a document from the recycle bin by its id delete-document-type Deletes a document type by Id delete-document-type-folder Deletes a document type folder by Id delete-element Deletes an element by Id + 35 more Every Mcp Dev tool, risk-classified, on the server page. delete-archived-server Delete an archived server (DELETE /orgs/{organization}/servers/archives/{server}). delete-background-process Delete a background process. delete-backup-configuration Delete a backup configuration. delete-backup-instance Delete a backup instance. delete-certificate Delete an SSL certificate. delete-composer-credential Delete a Composer credential (DELETE .../composer/credentials/{repository}). delete-database-schema Delete a database schema. delete-database-user Delete a database user. delete-deploy-key Delete the deploy key for a site. delete-domain Delete a domain. delete-firewall-rule Delete a firewall rule. delete-heartbeat Delete a heartbeat. + 35 more Every Laravel Forge tool, risk-classified, on the server page. bulk_file_operations Execute multiple file operations (move, copy, delete) sequentially in a single call. Returns per-item results. circles_delete Delete a circle/team. Requires owner privileges. circles_remove_member Remove a member from a circle/team. Use circles_list_members to get the memberId. Requires moderator privileges or higher. clear_out_of_office Clear a user's out-of-office / absence status (NC 28+) clear_user_status_message Clear the current user's custom status message delete Delete a file or folder from Nextcloud delete_all_form_submissions Delete every submission for a form. The form itself is kept. This cannot be undone. delete_all_notifications Delete all notifications for the current user delete_announcement Delete an announcement by its ID. Requires the configured Nextcloud user to be an admin. delete_bookmark Delete a bookmark by its ID. This action is irreversible. delete_bookmark_folder Delete a bookmark folder and all its contents. This action is irreversible. delete_bookmark_tag Delete a bookmark tag. The tag will be removed from all bookmarks. + 34 more Every AIquila — Nextcloud MCP Server tool, risk-classified, on the server page. acme_dns_authenticator_delete Delete an ACME DNS authenticator by its ID. alertservice_delete Delete an alert notification service by its ID. Use alertservice_list to find the ID. api_key_delete Delete an API key by its numeric ID. Use api_key_list to find the ID. This immediately revokes access for anyone using that key. app_delete Delete/uninstall an app. This is a DESTRUCTIVE operation. The app_rollback Rollback an app to a previous version. This is a DESTRUCTIVE operation. The boot_attach_disk Attach a disk to the boot pool to create or extend a mirror. This is a DESTRUCTIVE operation that will erase the target disk. The boot_detach_disk Detach a disk from the boot pool mirror. This is a DESTRUCTIVE operation — the bootenv_delete Delete a boot environment. This is a DESTRUCTIVE operation — the certificate_delete Delete a certificate by its ID. This is a DESTRUCTIVE operation — the cloud_backup_abort Abort a running cloud backup task cloud_backup_delete Delete a cloud backup task (destructive — requires confirm) cloudsync_credentials_delete Delete a cloud sync credential + 34 more Every Nasbridge tool, risk-classified, on the server page. acme_dns_authenticator_delete Delete an ACME DNS authenticator by its ID. alertservice_delete Delete an alert notification service by its ID. Use alertservice_list to find the ID. api_key_delete Delete an API key by its numeric ID. Use api_key_list to find the ID. This immediately revokes access for anyone using that key. app_delete Delete/uninstall an app. This is a DESTRUCTIVE operation. The app_rollback Rollback an app to a previous version. This is a DESTRUCTIVE operation. The boot_attach_disk Attach a disk to the boot pool to create or extend a mirror. This is a DESTRUCTIVE operation that will erase the target disk. The boot_detach_disk Detach a disk from the boot pool mirror. This is a DESTRUCTIVE operation — the bootenv_delete Delete a boot environment. This is a DESTRUCTIVE operation — the certificate_delete Delete a certificate by its ID. This is a DESTRUCTIVE operation — the cloud_backup_abort Abort a running cloud backup task cloud_backup_delete Delete a cloud backup task (destructive — requires confirm) cloudsync_credentials_delete Delete a cloud sync credential + 34 more Every Truenas tool, risk-classified, on the server page. gmail_delete_messages Delete Gmail messages. delete-email Delete an email by message ID delete-gmail-label Delete a gmail label. gcal_delete_event Delete a calendar event by its ID gmail_delete_draft Permanently delete an email draft gtasks_delete_task Delete a task permanently batch_delete_emails Delete multiple emails at once. By default moves to trash; use permanent=true for permanent deletion. delete_email Delete an email message. By default moves to trash; use permanent=true for permanent deletion. delete_filter Delete a Gmail filter by ID. delete_label Delete a user-created label. System labels cannot be deleted. delete_draft Delete an email draft. delete_email Delete a single email. + 33 more Every Gmail MCP Server tool, risk-classified, on the server page. clickup_delete_chat_channel clickup_delete_chat_channel clickup_delete_chat_message clickup_delete_chat_message clickup_delete_chat_reaction clickup_delete_chat_reaction clickup_delete_checklist clickup_delete_checklist clickup_delete_checklist_item clickup_delete_checklist_item clickup_delete_comment clickup_delete_comment clickup_delete_dependency clickup_delete_dependency clickup_delete_folder clickup_delete_folder clickup_delete_goal clickup_delete_goal clickup_delete_key_result clickup_delete_key_result clickup_delete_list clickup_delete_list clickup_delete_space clickup_delete_space + 33 more Every Clickup tool, risk-classified, on the server page. cancel_buy_request Cancel a Sanka Buy request before downstream purchasing is complete. cancel_export_job Cancel a running export job. cancel_import_job Cancel a running import job. cancel_workspace_invitation Cancel one pending invitation in an explicitly verified Sanka workspace. Call current_workspace immediately before this tool and pass its internal ... delete_absence Archive/delete an absence record in Sanka. delete_approval_rule Delete one approval rule for the specified object. delete_association Delete an association between two Sanka records. Prefer association_id; otherwise pass source_object/source_id, target_object/target_id, and label_... delete_attendance_record Archive/delete an employee attendance record in Sanka. delete_bill Delete a bill in Sanka by bill id or external reference. delete_company Archive or delete a company. Default target=sanka archives in Sanka only. Use target=integration with provider=salesforce to delete a Salesforce re... delete_contact Archive or delete a contact in Sanka or a connected CRM by contact id or external reference. delete_deal Archive or delete a deal in Sanka or a connected CRM by case id, numeric id, or external reference. + 32 more Every Sanka MCP Server tool, risk-classified, on the server page. account_delete Run account.delete through the Appaloft application operation catalog. Shared with HTTP/API. account_sessions_revoke Run account.sessions.revoke through the Appaloft application operation catalog. Shared with HTTP/API. audit_events_archives_prune Run audit-events.archives.prune through the Appaloft application operation catalog. Shared with CLI and HTTP/API. audit_events_prune Run audit-events.prune through the Appaloft application operation catalog. Shared with CLI and HTTP/API. certificates_delete Run certificates.delete through the Appaloft application operation catalog. Shared with CLI and HTTP/API. certificates_revoke Run certificates.revoke through the Appaloft application operation catalog. Shared with CLI and HTTP/API. connections_revoke Run connections.revoke through the Appaloft application operation catalog. Shared with CLI and HTTP/API. control_plane_portability_artifacts_delete Run control-plane-portability.artifacts.delete through the Appaloft application operation catalog. Shared with CLI and HTTP/API. credentials_delete_ssh Run credentials.delete-ssh through the Appaloft application operation catalog. Shared with CLI and HTTP/API. dependency_resources_delete Run dependency-resources.delete through the Appaloft application operation catalog. Shared with CLI and HTTP/API. deployments_archive Run deployments.archive through the Appaloft application operation catalog. Shared with CLI and HTTP/API. deployments_prune Run deployments.prune through the Appaloft application operation catalog. Shared with CLI and HTTP/API. + 31 more Every Appaloft tool, risk-classified, on the server page. autoload_remove Remove an autoload singleton from the project. node_delete node_delete delete_file Permanently delete a file from the project. REQUIRES confirm=true as an explicit safety gate — omitting confirm returns an error. Creates a .bak ba... remove_node Remove a node from an existing scene file. clear_editor_log Clear the editor output log clear_editor_selection Clear the current editor selection clear_output Clear the editor output log delete_export_preset Delete an export preset from the project delete_node Delete a node from the scene tree delete_particles Delete a particle system node from the scene delete_resource Delete a Godot resource file (.tres, .res) from the project delete_save_file Delete a save file from a specific slot + 31 more Every Godot tool, risk-classified, on the server page. archive_deployment Enterprise-gated. Archive a registered Gateway deployment by UUID. Use get_deployment first to confirm the target. Portkey soft-deletes the record;... cancel_log_export Cancel a pending or running log export job, unlike start_log_export which queues one or delete_integration which removes the source. This permanent... delete_api_key Delete an API key by UUID. This cannot be undone, revokes access immediately, and can break active sessions using the key. Returns success after re... delete_collection Delete a prompt collection by ID. This cannot be undone; prompts stay in the workspace but lose their collection grouping, so reassign them first i... delete_config Delete a config by slug. This is permanent, removes all versions, and breaks anything still pointing at that slug; check list_config_versions first. delete_guardrail Delete a guardrail by id or slug. This is irreversible and removes the check from any configs that reference it, so review dependent configs first. delete_integration Delete an integration by slug. This is irreversible and stops the org-level connection, which will break dependent virtual keys, providers, and wor... delete_integration_model Delete a custom model from an integration. Built-in models should be disabled instead, because deletion only applies to custom entries. Returns suc... delete_mcp_integration Delete an MCP integration and all servers beneath it. This is irreversible, removes connected access immediately, and should only be used after con... delete_mcp_server Delete an MCP server instance. This is irreversible, removes connected users delete_prompt Delete a prompt and all its versions by id. This cannot be undone, immediately breaks callers using the slug, and should only be used after checkin... delete_prompt_label Delete a prompt label by ID. This cannot be undone; versions carrying the label lose it, and any workflow resolving by that label will need a repla... + 31 more Every Portkey Admin tool, risk-classified, on the server page. asc_delete_accessibility_declaration DELETE /v1/accessibilityDeclarations/{id} — remove a DRAFT declaration. Published declarations are superseded by publishing a new draft (REPLACED),... asc_delete_alternative_distribution_domain ⚠️ DELETE /v1/alternativeDistributionDomains/{id} — apps distributed from this domain stop being installable from it. Confirm intent first. asc_delete_alternative_distribution_key ⚠️ DELETE /v1/alternativeDistributionKeys/{id} — artifacts signed against this key stop validating. Confirm intent first. asc_delete_analytics_report_request DELETE /v1/analyticsReportRequests/{id} — stop report generation for this request and drop access to its report chain. Recreating later starts fres... asc_delete_app_custom_product_page DELETE an AppCustomProductPage. Removes the page + every version + every localization + every asset set under it. The public CPP URL stops resolvin... asc_delete_app_custom_product_page_localization DELETE an AppCustomProductPageLocalization. Customers in this locale fall back to the parent AppStoreVersionLocalization. Apple may refuse if the p... asc_delete_app_custom_product_page_version DELETE an AppCustomProductPageVersion. Removes every localization + asset set under it. Apple gates this — versions in WAITING_FOR_REVIEW / IN_REVI... asc_delete_app_event DELETE an AppEvent. Removes the event + every localization + every asset. Apple may refuse if the event is PUBLISHED or IN_REVIEW. asc_delete_app_event_localization DELETE an AppEventLocalization. Removes the per-locale copy + every event screenshot + video clip under it. Customers in this locale fall back to t... asc_delete_app_event_screenshot DELETE an AppEventScreenshot. Removes the asset under its slot; if the slot goes empty Apple may reject the event for review with an asset-missing ... asc_delete_app_event_video_clip DELETE an AppEventVideoClip. Removes the video asset; if both screenshot + video slot are emptied, Apple may reject the event for review with an as... asc_delete_app_info_localization DELETE an AppInfoLocalization. The locale-specific app-level copy is removed (subtitle, privacy URLs, etc.). Customers in that locale fall back to ... + 31 more Every Appstoreconnect Mcp tool, risk-classified, on the server page. cancel_fulfillment_order Cancel a fulfillment order. cancel_order Cancel an order cancel_subscription_contract Cancel a subscription contract delete_app_proxy Delete an app proxy delete_cart_transform Delete a cart transform delete_channel Delete a sales channel delete_collection Delete a collection delete_company Delete a B2B company delete_company_contact Delete a company contact delete_custom_fulfillment_service Delete a custom fulfillment service delete_custom_pixel Delete a custom pixel delete_customer Delete a customer from the store + 31 more Every Shopify Graphql tool, risk-classified, on the server page. aos8_execute_migration_rollback aos8_execute_migration_rollback aos8_logout Log out of AOS8/Mobility Conductor and clear the cached session, if any. apstra_delete_connectivity_template Delete one Apstra connectivity template by ID. clear_alerts Clear one or more alerts by key. Returns the Central async task payload. clearpass_delete_endpoint Delete a ClearPass endpoint by MAC address. clearpass_delete_guest Delete a ClearPass guest account by username or ID. delete_aaa_profile Delete an AAA profile by name. delete_auth_profile Delete a Central NAC authentication profile by UUID. delete_auth_server Delete a RADIUS/auth server profile by name. delete_authz_policy Delete a CNAC authz policy by ID. delete_config_assignment delete_config_assignment delete_device_groups Bulk-delete device groups by scope ID list. + 30 more Every Hpe Networking tool, risk-classified, on the server page. aos8_execute_migration_rollback aos8_execute_migration_rollback aos8_logout Log out of AOS8/Mobility Conductor and clear the cached session, if any. apstra_delete_connectivity_template Delete one Apstra connectivity template by ID. clear_alerts Clear one or more alerts by key. Returns the Central async task payload. clearpass_delete_endpoint Delete a ClearPass endpoint by MAC address. clearpass_delete_guest Delete a ClearPass guest account by username or ID. delete_aaa_profile Delete an AAA profile by name. delete_auth_profile Delete a Central NAC authentication profile by UUID. delete_auth_server Delete a RADIUS/auth server profile by name. delete_authz_policy Delete a CNAC authz policy by ID. delete_config_assignment delete_config_assignment delete_device_groups Bulk-delete device groups by scope ID list. + 30 more Every API-Central tool, risk-classified, on the server page. bulk_action Perform an action on up to 50 messages at once. Actions: read, unread, star, unstar, delete, move, spam, notspam. The cancel_bulk_migration Cancel an active bulk migration batch. All queued and running jobs will be stopped. Set confirm_cancel=true to proceed. cancel_migration Cancel a running email migration. Set confirm_cancel=true to proceed. cancel_scheduled Cancel a pending scheduled message. Requires TREKMAIL_ALLOW_DESTRUCTIVE=true. change_mailbox_password Change the password of a mailbox. Requires TREKMAIL_ALLOW_DESTRUCTIVE=true because password changes are irreversible. confirm_delete_intent Confirm a delete intent to delete a mailbox. This is step 2 of the two-step deletion process. The mailbox is moved to the recycle bin and can be re... create_delete_intent Create a delete intent for a mailbox. This is step 1 of the two-step deletion process. Returns an intent that expires in 10 minutes. The intent mus... delete_alias Permanently remove an email alias from a mailbox. Mail sent to this address will no longer be delivered. This cannot be undone. delete_bulk_migration Delete a completed, failed, or cancelled bulk migration batch record. Cannot delete active batches. Both TREKMAIL_ALLOW_MIGRATION=true and confirm_... delete_calendar_event Delete a calendar event. Requires TREKMAIL_ALLOW_DESTRUCTIVE=true. delete_cloudflare_token Delete a saved Cloudflare token and disconnect all domains using it. Domains remain in TrekMail but lose their Cloudflare connection. delete_contact Delete a contact. Requires TREKMAIL_ALLOW_DESTRUCTIVE=true. + 30 more Every TrekMail MCP Server tool, risk-classified, on the server page. discord_ban_user Ban a user from a guild. discord_bulk_delete_messages Bulk delete 2-100 messages (must be <14 days old). discord_clear_all_reactions Remove all reactions from a message. discord_delete_channel Delete a channel. discord_delete_command Delete a slash command. discord_delete_emoji Delete a custom emoji. discord_delete_guild_sticker Delete a guild sticker. discord_delete_invite Delete an invite by code. discord_delete_reaction Remove your bot reaction from a message. discord_delete_role Delete a role in a guild. discord_delete_scheduled_event Delete a scheduled event. discord_kick_member Kick (remove) a member from a guild. + 29 more Every Discord MCP Server tool, risk-classified, on the server page. bulk_delete_social_posts Delete multiple social media posts at once (max 50) cancel_scheduled_email Cancel a scheduled email before it is sent cancel_scheduled_message Cancel a scheduled message before it is sent delete_appointment Cancel/delete an appointment from GoHighLevel delete_appointment_note Delete an appointment note delete_calendar Delete a calendar from GoHighLevel delete_calendar_group Delete a calendar group delete_calendar_notification Delete calendar notification delete_calendar_resource_equipment Delete an equipment resource delete_calendar_resource_room Delete a room resource delete_contact Delete a contact from GoHighLevel delete_contact_note Delete a note for a contact + 29 more Every Ghl tool, risk-classified, on the server page. Showing the 50 servers with the most destructive tools — 11436 servers in the catalogue expose them. Find the rest through tool search or the policy library.
BROWSE OTHER CATEGORIES
FREQUENTLY ASKED QUESTIONS
Tools that permanently delete or destroy resources. Critical risk -- block by default. There are 37287 destructive tools across 11436 MCP servers in the PolicyLayer reference.
Destructive tools should be blocked by default. Only enable with explicit human approval workflows.
GoHighLevel MCP Server, Pfsense, Huly, Mcp, Discord, and 11431 more.