Critical-risk tools in Mcp Jazzcash
3 of the 5 tools in Mcp Jazzcash are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
jazzcash_charge_mobile_walletFinancialServer-to-server charge against a JazzCash mobile wallet. Customer authorizes via MPIN on their phone. Amount is in PKR paisa.
-
jazzcash_refund_transactionFinancialIssue a full or partial refund against a previously settled JazzCash transaction. Requires the merchant account to have refund permissions enabled.
-
jazzcash_create_hosted_checkoutFinancialBuild a signed Hosted Checkout (Page Redirection) form that redirects the customer to JazzCash to pay. Returns the action URL, hidden fields, and a ready-to-use HTML form snippe...
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.