Critical-risk tools in Carrier MCP: Give Your AI Agent Global Connectivity
6 of the 65 tools in Carrier MCP: Give Your AI Agent Global Connectivity are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
change_sim_statusDestructiveUse this to change the physical SIM/eSIM card status at the SIM provider level, independent of the OCS subscriber lifecycle status. Statuses: ENABLED (normal operation), DISABLE...
-
clean_all_packagesDestructiveDANGEROUS: Removes ALL prepaid packages from a subscriber in a single irreversible operation. There is no undo. Typical use: resetting a subscriber to zero before re-provisionin...
-
delete_subscriber_packageDestructiveUse this to permanently remove a single prepaid package from a subscriber. This is irreversible — the package record and any unused allowance are deleted. Always call `list_subs...
-
modify_subscriber_statusDestructiveUse this to change the OCS lifecycle status of a subscriber. Common transitions: ACTIVE → SUSPENDED (pause without losing packages), SUSPENDED → ACTIVE (reactivate), ACTIVE/SUSP...
-
reset_subscriber_gz_counterDestructiveADMIN: Use this to reset the Gz (Diameter accounting) usage counter for a subscriber. Typically used after a billing dispute or test-cycle reset where accumulated usage data mus...
-
stop_resume_recurring_packageDestructiveUse this to pause or restart the auto-renewal cycle of a recurring package without removing it. 'stop' halts future renewals (subscriber keeps current period until expiry); 'res...
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.