Guard Destructive Actions
Require confirmation before irreversible operations.
Some Actions Cannot Be Undone
Deleting records, sending emails, charging cards, and pushing code are irreversible operations. These deserve more caution than a harmless read. ⚠️
Reversibility Is the Test
Ask one question of each tool: can I easily undo this? If the answer is no, treat it as high risk and wrap it in extra safeguards before it can run.
All lessons in this course
- Threats Unique to MCP
- Least-Privilege Tool Access
- Validate & Sanitize Everything
- Guard Destructive Actions