High-risk tools in cPanel MCP Server
10 of the 164 tools in cPanel MCP Server are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
deploy_git_repoExecuteDeploy a Git repository (trigger deployment via .cpanel.yml)
-
start_virus_scanExecuteStart a ClamAV virus scan on a directory (requires ClamAV plugin on server)
-
trigger_autosslExecuteTrigger an AutoSSL check/renewal for the account
-
disable_modsecurityExecuteDisable ModSecurity (WAF) for all domains
-
disable_modsecurity_domainExecuteDisable ModSecurity for specific domains
-
disable_passenger_appExecuteDisable/stop a registered application
-
enable_passenger_appExecuteEnable/start a registered application
-
ensure_passenger_depsExecuteInstall/update dependencies for a registered application (npm install, pip install, etc.)
-
trace_email_filterExecuteTest email filters against a message to see which rules match
-
update_git_repoExecutePull/update a Git repository
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.