Shutdown or restart the system (Windows or Mac) 关机的时候,调用这个工具
AI agents invoke shutdown_system to trigger actions in PC-MCP. What it does depends on the arguments the agent supplies, and its effects often reach beyond the immediate call — builds kicked off, notifications sent, workflows started.
This tool executes a critical system command (shutdown/restart) that affects the entire operating system. While the action is not data destruction, it is an Execute category tool because it runs a system-level operation whose effects are immediate and depend on the arguments (shutdown vs restart).
From the tool's definition Tool named 'shutdown_system' with description stating it will 'Shutdown or restart the system (Windows or Mac)'. This triggers an external system operation with irreversible immediate effects during tool execution.
Documented attack patterns abuse exactly the kind of access shutdown_system gives an agent:
PolicyLayer is an MCP gateway — it sits between your AI agents and PC-MCP, and nothing reaches the server without passing your rules. This is the rule we recommend for shutdown_system:
{
"version": "1",
"default": "deny",
"tools": {
"shutdown_system": {
"limits": [
{
"counter": "shutdown_system_rate",
"window": "minute",
"max": 10,
"scope": "grant"
}
]
}
}
} shutdown_system stays usable, but rate-capped — a runaway agent can't fire it dozens of times a minute. Everything else on the server is denied unless you say otherwise.
Free to start. No card required.
Shutdown or restart the system (Windows or Mac) 关机的时候,调用这个工具. It is categorised as a Execute tool in the PC-MCP MCP Server, which means it can trigger actions or run processes. Use rate limits and argument validation.
Register the PC- MCP server in PolicyLayer and add a rule for shutdown_system: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches PC-MCP. Nothing to install.
shutdown_system is a Execute tool with high risk. Execute tools should be rate-limited and have argument validation enabled.
Yes. Add a rate_limit block to the shutdown_system rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for shutdown_system. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
shutdown_system is provided by the PC- MCP server (shijianzhong/mcp-server-for-pc). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
Start from PC-MCP, add the rest of your stack, and see everything your agents can call. Then put policy on all of it.
Free to start. No card required.
6 PC-MCP tools catalogued and risk-classified — across an index of 43,000+ MCP servers.