Critical-risk tools in Unofficial FortiMonitor MCP Server
29 of the 272 tools in Unofficial FortiMonitor MCP Server are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
clear_webhook_eventsDestructiveClear all stored webhook events.
-
delete_agent_resource_thresholdDestructiveDelete an agent resource threshold. This removes the
-
delete_cloud_credentialDestructiveDelete a cloud credential.
-
delete_compound_serviceDestructiveDelete a compound service. The underlying servers and checks are not affected.
-
delete_contactDestructiveDelete a notification contact. This removes them from all
-
delete_contact_groupDestructiveDelete a contact group. The contacts within the group are not deleted.
-
delete_contact_infoDestructiveRemove a contact method (email, SMS, phone, etc.) from a contact.
-
delete_dashboardDestructiveDelete a dashboard. This permanently removes the dashboard
-
delete_dem_applicationDestructiveDelete a DEM application and all its associated monitoring instances.
-
delete_fabric_connectionDestructiveDelete a fabric connection from FortiMonitor.
-
delete_maintenance_scheduleDestructiveDelete a maintenance schedule.
-
delete_network_serviceDestructiveDelete a network service (monitoring check) from a server.
-
delete_network_service_countermeasureDestructiveDelete a countermeasure from a network service.
-
delete_notification_scheduleDestructiveDelete a notification schedule. Servers and contact groups using this
-
delete_onsightDestructiveDelete an OnSight instance.
-
delete_onsight_groupDestructiveDelete an OnSight group.
-
delete_rotating_contactDestructiveDelete a rotating contact schedule.
-
delete_serverDestructiveDelete a monitored server from FortiMonitor.
-
delete_server_attributeDestructiveDelete a custom attribute from a server.
-
delete_server_attribute_typeDestructiveDelete a server attribute type. Any attributes of this type
-
delete_server_groupDestructiveDelete a server group.
-
delete_server_path_monitoringDestructiveDelete a path monitoring configuration from a server.
-
delete_server_templateDestructiveDelete a server monitoring template.
-
delete_snmp_credentialDestructiveDelete an SNMP credential.
-
delete_snmp_resourceDestructiveDelete an SNMP resource from a server.
-
delete_status_pageDestructiveDelete a public status page. This permanently removes the page.
-
delete_threshold_countermeasureDestructiveDelete a countermeasure from an agent resource threshold.
-
delete_userDestructiveDelete a user from FortiMonitor.
-
force_resolve_outageDestructiveForce resolve a manual or custom incident.
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.