High-risk tools in Mcp Nettools
8 of the 235 tools in Mcp Nettools are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
check_mqttExecuteConnect to an MQTT broker and send a CONNECT packet (v3.1.1). Checks for a CONNACK response and decodes the return code. port: 1883 (plain) or 8883 (TLS). Does not authenticate ...
-
check_rdpExecutecheck_rdp
-
http_postExecutehttp_post
-
pingExecutePing a host and return reachability, packet loss %, and RTT stats. count: 1-30. timeout: 1-60 s per packet.
-
port_scanExecuteCheck multiple TCP ports on a host. ports: comma-separated or ranges (e.g., '22,80,443,8000-8080'). Max 500 ports. timeout: 1-30 s. open_only: if True, omit closed ports from th...
-
speedtestExecuteRun a network speed test using the nearest server.
-
tracerouteExecuteTrace the network path to a host. max_hops: 1-64. timeout: overall timeout in seconds. wait: per-hop probe wait time in seconds (1-10, default 2; increase to 5-10 for high-laten...
-
wake_on_lanExecuteSend a Wake-on-LAN magic packet to a MAC address.
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.