30309 tools

DESTRUCTIVE MCP TOOLS

Tools that permanently delete or destroy resources. Critical risk -- block by default.

Severity: Critical severity →

Real-world attack patterns documented against destructive-class MCP tools. Each links to the full case and the defensive policy.

Browse the full MCP Attack Database →

BINANCE MCP SERVER

54 All Binance MCP Server tools →
cancel_order Cancel a specific order. binance_us_cancel_all_open_orders Cancel all active orders on a symbol on Binance.US. This includes OCO orders. Use with caution - this will cancel ALL open orders for the specified... binance_us_cancel_oco Cancel an entire OCO order on Binance.US. Cancelling any individual leg will cancel the entire OCO. binance_us_cancel_order Cancel an active order on Binance.US. Either orderId or origClientOrderId must be provided. binance_us_cancel_replace Cancel an existing order and place a new order on the same symbol atomically. This is useful for modifying order parameters. binance_us_cust_cancel_oco Cancel an entire OCO (One-Cancels-the-Other) order list. ⚠️ REQUIRES CUSTODIAL SOLUTION API KEY This cancels both legs of the OCO order. Respons... binance_us_cust_cancel_order Cancel an active custodial trade order. ⚠️ REQUIRES CUSTODIAL SOLUTION API KEY Either orderId or origClientOrderId must be provided. Response in... binance_us_cust_cancel_orders_symbol Cancel all active custodial orders for a specific trading pair. ⚠️ REQUIRES CUSTODIAL SOLUTION API KEY This includes OCO orders. Use with caution... BinanceCancelHashRateResaleConfiguration Cancel an existing hashrate resale configuration using the mining ID and account details. BinanceConvertCancelLimitOrder Cancels a previously placed limit order using the orderId and returns the cancellation status along with the orderId. BinanceCrossMarginCancelAllOrders Cancel all open margin orders for a specific trading pair. This will cancel all open orders on the symbol. BinanceCrossMarginCancelOrder Cancel an active margin order. Either orderId or origClientOrderId must be provided. + 42 more Every Binance MCP Server tool, risk-classified, on the server page.
caddy_remove_site Remove a site block from the Caddyfile (matched by address) and reload Caddy. Destructive — the change is persisted to disk. crow_bookstack_delete Delete a page or chapter from BookStack (irreversible) crow_campaign_delete Delete a campaign and all its posts. Requires confirmation. crow_data_write Execute a write SQL statement (INSERT, CREATE TABLE, UPDATE, DELETE) on a user-owned database. Separate from read-only queries for safety. crow_deactivate_server Deactivate a server crow_delete_bot_schedule Delete a recurring bot-cron schedule by its scheduleId (from crow_list_bot_schedules). crow_delete_context_section Delete a custom crow.md section. Protected sections cannot be deleted — only disabled. Scoped overrides (device/project) of protected sections CAN ... crow_delete_file Permanently delete a file from storage. This cannot be undone. Returns a preview and confirmation token on first call; pass the token back to execute. crow_delete_memory Permanently delete a memory. This cannot be undone. Returns a preview and confirmation token on first call; pass the token back to execute. crow_delete_post Permanently delete a blog post. This cannot be undone — use crow_unpublish_post to revert to draft instead. Returns a preview and confirmation toke... crow_delete_setlist Permanently delete a setlist. Returns a preview and confirmation token on first call; pass the token back to execute. crow_frigate_set_detect Enable/disable motion detection for a camera. DESTRUCTIVE: disabling detect also stops motion-triggered recording on that camera. Use sparingly. + 36 more Every Crow tool, risk-classified, on the server page.

APPSTORECONNECT MCP

42 All Appstoreconnect Mcp tools →
asc_delete_accessibility_declaration DELETE /v1/accessibilityDeclarations/{id} — remove a DRAFT declaration. Published declarations are superseded by publishing a new draft (REPLACED),... asc_delete_alternative_distribution_domain ⚠️ DELETE /v1/alternativeDistributionDomains/{id} — apps distributed from this domain stop being installable from it. Confirm intent first. asc_delete_alternative_distribution_key ⚠️ DELETE /v1/alternativeDistributionKeys/{id} — artifacts signed against this key stop validating. Confirm intent first. asc_delete_analytics_report_request DELETE /v1/analyticsReportRequests/{id} — stop report generation for this request and drop access to its report chain. Recreating later starts fres... asc_delete_app_custom_product_page DELETE an AppCustomProductPage. Removes the page + every version + every localization + every asset set under it. The public CPP URL stops resolvin... asc_delete_app_custom_product_page_localization DELETE an AppCustomProductPageLocalization. Customers in this locale fall back to the parent AppStoreVersionLocalization. Apple may refuse if the p... asc_delete_app_custom_product_page_version DELETE an AppCustomProductPageVersion. Removes every localization + asset set under it. Apple gates this — versions in WAITING_FOR_REVIEW / IN_REVI... asc_delete_app_event DELETE an AppEvent. Removes the event + every localization + every asset. Apple may refuse if the event is PUBLISHED or IN_REVIEW. asc_delete_app_event_localization DELETE an AppEventLocalization. Removes the per-locale copy + every event screenshot + video clip under it. Customers in this locale fall back to t... asc_delete_app_event_screenshot DELETE an AppEventScreenshot. Removes the asset under its slot; if the slot goes empty Apple may reject the event for review with an asset-missing ... asc_delete_app_event_video_clip DELETE an AppEventVideoClip. Removes the video asset; if both screenshot + video slot are emptied, Apple may reject the event for review with an as... asc_delete_app_info_localization DELETE an AppInfoLocalization. The locale-specific app-level copy is removed (subtitle, privacy URLs, etc.). Customers in that locale fall back to ... + 30 more Every Appstoreconnect Mcp tool, risk-classified, on the server page.

PORTKEY ADMIN

41 All Portkey Admin tools →
cancel_log_export Cancel a pending or running log export job, unlike start_log_export which queues one or delete_integration which removes the source. This permanent... delete_api_key Delete an API key by UUID. This cannot be undone, revokes access immediately, and can break active sessions using the key. Returns success after re... delete_collection Delete a prompt collection by ID. This cannot be undone; prompts stay in the workspace but lose their collection grouping, so reassign them first i... delete_config Delete a config by slug. This is permanent, removes all versions, and breaks anything still pointing at that slug; check list_config_versions first. delete_guardrail Delete a guardrail by id or slug. This is irreversible and removes the check from any configs that reference it, so review dependent configs first. delete_integration Delete an integration by slug. This is irreversible and stops the org-level connection, which will break dependent virtual keys, providers, and wor... delete_integration_model Delete a custom model from an integration. Built-in models should be disabled instead, because deletion only applies to custom entries. Returns suc... delete_mcp_integration Delete an MCP integration and all servers beneath it. This is irreversible, removes connected access immediately, and should only be used after con... delete_mcp_server Delete an MCP server instance. This is irreversible, removes connected users delete_prompt Delete a prompt and all its versions by id. This cannot be undone, immediately breaks callers using the slug, and should only be used after checkin... delete_prompt_label Delete a prompt label by ID. This cannot be undone; versions carrying the label lose it, and any workflow resolving by that label will need a repla... delete_prompt_partial Delete a prompt partial by ID. This cannot be undone, and prompts that reference it with {{> name}} will fail to render until you replace the refer... + 29 more Every Portkey Admin tool, risk-classified, on the server page.

TREKMAIL MCP SERVER

41 All TrekMail MCP Server tools →
bulk_action Perform an action on up to 50 messages at once. Actions: read, unread, star, unstar, delete, move, spam, notspam. The cancel_bulk_migration Cancel an active bulk migration batch. All queued and running jobs will be stopped. Set confirm_cancel=true to proceed. cancel_migration Cancel a running email migration. Set confirm_cancel=true to proceed. cancel_scheduled Cancel a pending scheduled message. Requires TREKMAIL_ALLOW_DESTRUCTIVE=true. change_mailbox_password Change the password of a mailbox. Requires TREKMAIL_ALLOW_DESTRUCTIVE=true because password changes are irreversible. confirm_delete_intent Confirm a delete intent to delete a mailbox. This is step 2 of the two-step deletion process. The mailbox is moved to the recycle bin and can be re... create_delete_intent Create a delete intent for a mailbox. This is step 1 of the two-step deletion process. Returns an intent that expires in 10 minutes. The intent mus... delete_alias Permanently remove an email alias from a mailbox. Mail sent to this address will no longer be delivered. This cannot be undone. delete_bulk_migration Delete a completed, failed, or cancelled bulk migration batch record. Cannot delete active batches. Both TREKMAIL_ALLOW_MIGRATION=true and confirm_... delete_calendar_event Delete a calendar event. Requires TREKMAIL_ALLOW_DESTRUCTIVE=true. delete_cloudflare_token Delete a saved Cloudflare token and disconnect all domains using it. Domains remain in TrekMail but lose their Cloudflare connection. delete_contact Delete a contact. Requires TREKMAIL_ALLOW_DESTRUCTIVE=true. + 29 more Every TrekMail MCP Server tool, risk-classified, on the server page.

DATAVERSE MCP SERVER

39 All Dataverse MCP Server tools →
dataverse_delete_record Delete a record from a Dataverse table convert_owner_team_to_access_team Converts an owner team to an access team, changing how the team can be used for record ownership and sharing. WARNING: This action cannot be undone... delete_dataverse_businessunit Permanently deletes a business unit from Dataverse. WARNING: This action cannot be undone and may affect users and teams associated with the busine... delete_dataverse_column Permanently deletes a column from a Dataverse table. WARNING: This action cannot be undone and will remove all data stored in this column. Use with... delete_dataverse_optionset Permanently deletes an option set from Dataverse. WARNING: This action cannot be undone and will fail if the option set is being used by any column... delete_dataverse_relationship Permanently deletes a relationship between Dataverse tables. WARNING: This action cannot be undone and will remove the connection between tables, i... delete_dataverse_role Permanently deletes a security role from Dataverse. WARNING: This action cannot be undone and will fail if the role is assigned to any users or tea... delete_dataverse_table Permanently deletes a custom table from Dataverse. WARNING: This action cannot be undone and will remove all data in the table. Use with extreme ca... delete_dataverse_team Permanently deletes a team from Dataverse. WARNING: This action cannot be undone and will fail if the team owns records or has assigned security ro... remove_members_from_team Removes users from team membership, revoking their access to team-owned records and team-based permissions. Use this when users no longer need team... remove_privilege_from_role Removes a specific privilege from a security role, revoking the associated permissions. Use this to restrict access by removing specific operation ... remove_role_from_team Removes a security role assignment from a team, revoking the permissions granted by that role for all team members. Use this when teams no longer n... + 27 more Every Dataverse MCP Server tool, risk-classified, on the server page.

Showing the 50 servers with the most destructive tools — 9123 servers in the catalogue expose them. Find the rest through tool search or the policy library.

FREQUENTLY ASKED QUESTIONS

Tools that permanently delete or destroy resources. Critical risk -- block by default. There are 30309 destructive tools across 9123 MCP servers in the PolicyLayer reference.

Destructive tools should be blocked by default. Only enable with explicit human approval workflows.

GoHighLevel MCP Server, Pfsense, Huly, AdButler, Discord, and 9118 more.

Take your agents live. Without losing control.

Route your MCP traffic through PolicyLayer. Every tool call is checked against your policy before it runs: allow, deny, or require approval. Per-identity grants. Full audit log. Live in minutes.

Instant setup, no code required.

46,500+ MCP servers and 515,000+ tools scanned and risk-classified.

// GET IN TOUCH

Have a question or want to learn more? Send us a message.

Message sent.

We'll get back to you soon.