High-risk tools in Mcp Mautic
6 of the 229 tools in Mcp Mautic are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
mautic_generate_tracking_pixel_urlExecuteGenerate a Mautic tracking pixel URL (/mtracking.gif) for synthetic page hit injection. Supports tag manipulation: prefix tag with
-
mautic_send_email_to_contactExecuteSend email to contact. Supports custom tokens (dynamic placeholders like {custom_link}) and asset attachments. Tokens replace {token_name} in email body at send time.
-
mautic_send_email_to_segmentExecuteSend email to segment
-
mautic_send_message_to_contactExecuteSend a marketing message (multi-channel) to a specific contact. Mautic selects the best channel (email, SMS, notification) based on contact preferences.
-
mautic_send_sms_to_contactExecuteSend an SMS to a specific contact.
-
mautic_track_custom_eventExecuteTrack a custom event for a contact via the /mtc/event/track endpoint. This is a public endpoint (no auth required) used for custom behavioral tracking. The event can trigger cam...
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.