Critical-risk tools in Samarth Gtm Mcp
21 of the 236 tools in Samarth Gtm Mcp are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
built_in_variables_disableDestructive[DELETE] Disable one or more built-in variables in a GTM workspace.
-
delete_ga4_accountDestructive[GA4] Soft-delete (trash) an entire GA4 account and all its properties. High blast radius. Destructive — two-step approval.
-
delete_ga4_propertyDestructive[GA4] Soft-delete (trash) a GA4 property — recoverable for a limited time. Destructive — two-step approval.
-
delete_gtm_clientDestructiveDelete a CLIENT from a SERVER container workspace (draft, not published). The GTM API DOES support this (workspaces.clients.delete); do NOT tell the user clients can only be rem...
-
delete_gtm_folderDestructiveDelete a GTM folder (draft, not published). GTM does NOT delete its contents: the tags/triggers/variables become unfiled. Destructive, requires two confirmations.
-
delete_gtm_tagDestructiveDelete a tag from a GTM workspace (draft, not published). Destructive, requires two confirmations.
-
delete_gtm_triggerDestructiveDelete a trigger from a GTM workspace (draft, not published). Applies the audit fix for an unused trigger. Destructive, requires two confirmations.
-
delete_gtm_variableDestructiveDelete a variable from a GTM workspace (draft, not published). Destructive, requires two confirmations; verify it is not used by a published version first.
-
delete_unused_gtm_triggersDestructiveBulk-delete the UNUSED (orphaned) triggers in a GTM workspace: referenced by no tag (firing or blocking) and not a Trigger Group member. By DEFAULT deletes ALL unused ones; pass...
-
delete_unused_gtm_variablesDestructiveBulk-delete the UNUSED (orphaned) variables in a GTM workspace: {{name}} referenced by no tag, trigger or other variable in the readable fields. By DEFAULT deletes ALL unused on...
-
environments_deleteDestructive[DELETE] Delete a GTM environment. Requires GTM_MCP_ENABLE_DELETES=true and confirm=true.
-
folders_deleteDestructive[DELETE] Delete a GTM folder. Requires GTM_MCP_ENABLE_DELETES=true and confirm=true. Contents of the folder will be unfoldered, not deleted.
-
forget_memoryDestructiveRemove saved memories matching a description. Call this when the user says to forget or stop applying
-
ga4_delete_accountDestructive[GA4 DELETE] Soft-delete (trash) an entire GA4 account and all its properties. High blast radius — recoverable from the trash for a limited time.
-
ga4_delete_propertyDestructive[GA4 DELETE] Soft-delete (trash) a GA4 property. It is recoverable from the trash for a limited time, then permanently removed.
-
tags_deleteDestructive[DELETE] Delete a GTM tag. Requires GTM_MCP_ENABLE_DELETES=true and confirm=true.
-
triggers_deleteDestructive[DELETE] Delete a GTM trigger. Requires GTM_MCP_ENABLE_DELETES=true and confirm=true.
-
user_permissions_deleteDestructive[DELETE] Revoke a user\
-
variables_deleteDestructive[DELETE] Delete a GTM variable. Requires GTM_MCP_ENABLE_DELETES=true and confirm=true.
-
versions_deleteDestructive[DELETE] Delete a GTM container version.
-
update_google_ads_campaign_budgetFinancialChange a DAILY campaign budget (in MICROS of the account currency: 50 units = 50000000). The result returns
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.