Critical-risk tools in CDP MCP Server
38 of the 288 tools in CDP MCP Server are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
cdp_cache_delete_by_groupDestructiveDelete a cache entry by group and ID. Returns 204 on success.
-
cdp_cache_delete_by_idDestructiveDelete a cache entry by ID. Returns 204 on success.
-
cdp_cache_delete_by_keyDestructiveDelete a cache entry by explicit key. Returns 204 on success.
-
cdp_deactivate_provision_instanceDestructiveDeactivate a provisioned instance (DELETE /provisions/instances/{id}).
-
cdp_delete_a360_ruleDestructiveDelete an A360 rule
-
cdp_delete_alertDestructiveDelete/dismiss a triggered alert
-
cdp_delete_alert_defDestructiveDelete an alert definition
-
cdp_delete_audience_defDestructiveDelete an audience definition
-
cdp_delete_campaignDestructiveDelete a campaign definition by ID
-
cdp_delete_clientDestructiveDelete an OAuth client by numeric ID
-
cdp_delete_column_validatorDestructiveDelete a column validator
-
cdp_delete_connectorDestructiveDelete a connector
-
cdp_delete_connector_templateDestructiveDelete a connector definition
-
cdp_delete_cubic_set_defDestructiveDelete a CubicSetDef by ID
-
cdp_delete_dashboardDestructiveDelete a dashboard by ID
-
cdp_delete_data_erasure_requestDestructiveCancel/delete a pending data erasure request
-
cdp_delete_data_exportDestructiveDelete a data export definition by ID.
-
cdp_delete_dispatchDestructiveDelete a dispatch definition
-
cdp_delete_emailable_pageDestructivecdp_delete_emailable_page
-
cdp_delete_execution_bucketDestructiveDelete an execution bucket
-
cdp_delete_execution_summary_groupDestructiveDelete an execution summary group
-
cdp_delete_mapping_templateDestructiveDelete a mapping template
-
cdp_delete_message_defDestructiveDelete a message definition by ID
-
cdp_delete_output_connectorDestructiveDelete an output connector
-
cdp_delete_output_connector_defDestructiveDelete an output connector definition
-
cdp_delete_predictionDestructiveDelete a prediction definition (DELETE /v2/{tenantId}/campaign/predictionDefs/{id}).
-
cdp_delete_report_defDestructiveDelete a report definition by ID
-
cdp_delete_roleDestructiveDelete a role by ID
-
cdp_delete_scheduleDestructivecdp_delete_schedule
-
cdp_delete_selfservice_userDestructiveDelete a self-service user by ID
-
cdp_delete_squery_defDestructiveDelete a SQueryDef by ID.
-
cdp_delete_userDestructiveDelete a CDP user by ID
-
cdp_delete_widgetDestructiveDelete a widget by ID
-
cdp_deprovision_instanceDestructivecdp_deprovision_instance
-
cdp_purge_dataDestructivePurge customer data from the data warehouse.
-
cdp_request_data_erasureDestructivecdp_request_data_erasure
-
cdp_revoke_tokenDestructivecdp_revoke_token
-
cdp_update_data_erasure_requestDestructivecdp_update_data_erasure_request
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.