Critical-risk tools in UniFi Access MCP
23 of the 272 tools in UniFi Access MCP are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
access_delete_visitorDestructiveaccess_delete_visitor
-
access_revoke_credentialDestructiveaccess_revoke_credential
-
protect_alarm_delete_ruleDestructiveprotect_alarm_delete_rule
-
protect_delete_known_faceDestructiveprotect_delete_known_face
-
protect_delete_known_license_plateDestructiveprotect_delete_known_license_plate
-
protect_delete_liveviewDestructiveprotect_delete_liveview
-
protect_delete_recordingDestructiveprotect_delete_recording
-
unifi_delete_acl_ruleDestructiveDelete a MAC ACL rule. Requires confirmation. WARNING: Removing an ALLOW rule
-
unifi_delete_ap_groupDestructiveunifi_delete_ap_group
-
unifi_delete_backupDestructiveDelete a backup file from the controller. Use unifi_list_backups to find filenames.
-
unifi_delete_client_groupDestructiveDelete a client group. Requires confirmation.
-
unifi_delete_content_filterDestructiveDelete a content filtering profile. Requires confirmation.
-
unifi_delete_dns_recordDestructiveDelete a static DNS record. Use unifi_list_dns_records to find record IDs. Requires confirmation.
-
unifi_delete_dynamic_dnsDestructiveDelete a Dynamic DNS entry. Use unifi_list_dynamic_dns to find entry IDs. Requires confirmation.
-
unifi_delete_firewall_groupDestructiveDelete a firewall group. Requires confirmation.
-
unifi_delete_firewall_policyDestructiveunifi_delete_firewall_policy
-
unifi_delete_oon_policyDestructiveDelete an OON policy. Requires confirmation.
-
unifi_delete_port_forwardDestructiveDelete a port forwarding rule by ID. Requires confirmation.
-
unifi_delete_port_profileDestructiveDelete a port profile. System profiles with attr_no_delete=true cannot be deleted.
-
unifi_delete_wlanDestructiveunifi_delete_wlan
-
unifi_forget_clientDestructiveRemove/forget a client from the controller
-
unifi_revoke_voucherDestructiveRevoke/delete a hotspot voucher by its ID, preventing further use
-
unifi_unauthorize_guestDestructiveRevoke authorization for a guest client by MAC address
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.