High-risk tools in Carrier MCP: Give Your AI Agent Global Connectivity
3 of the 65 tools in Carrier MCP: Give Your AI Agent Global Connectivity are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
balance_topup_formExecuteEnterprise admin tool: preview or commit an account balance adjustment. Set preview=true to fetch projection (no OCS write); preview=false (default) to execute. Requires admin s...
-
subscriber_network_eventsExecuteUse this to retrieve timestamped network events for a subscriber: attach, detach, location updates, and handovers between operators. Useful for connectivity troubleshooting, roa...
-
subscriber_usageExecuteUse this to retrieve daily data, voice, and SMS usage for a subscriber over a date range. Hard limit: maximum 7 days per query — do not exceed or OCS will return an error. Param...
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.