High-risk tools in Appstoreconnect Mcp
8 of the 278 tools in Appstoreconnect Mcp are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
asc_patch_review_submissionExecuteTrigger the submit or cancel action on a review submission. The action enum (submit | cancel) is the friendly wrapper around Apple
-
asc_patch_version_experimentExecute⚠️ started=true is CUSTOMER-FACING: PATCH /v2/appStoreVersionExperiments/{id} with started=true begins serving treatment pages to real App Store traffic (requires state APPROVED...
-
asc_post_alternative_distribution_packageExecutePOST /v1/alternativeDistributionPackages — start packaging an App Store Version for alternative distribution. Relationships-only body (appStoreVersion). Apple builds the signed ...
-
asc_post_beta_app_review_submissionExecuteSubmit a build for Apple beta review. Required: buildId. The body has NO attributes — only the build relationship. Once submitted, betaReviewState walks WAITING_FOR_REVIEW → IN_...
-
asc_post_webhook_pingExecutePOST /v1/webhookPings — have Apple send a test event to the webhook endpoint NOW (arrives with ping=true in the payload). The response resource is id-only; check the result via ...
-
asc_post_webhook_redeliveryExecutePOST /v1/webhookDeliveries — re-send a previous delivery (typically a FAILED one from asc_list_webhook_deliveries). The body carries only a
-
asc_sign_introductory_offer_eligibilityExecuteSign a JWS that overrides StoreKit\
-
asc_sign_promotional_offerExecuteSign a promotional-offer redemption payload using the JWS v2 format (recommended for new code; introduced WWDC 2025, back-deployed to iOS 15). Use this when your iOS app uses St...
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.