High-risk tools in Sequenzy Mcp
16 of the 222 tools in Sequenzy Mcp are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
realign_sequence_enrollmentsExecutePull waiting enrollments forward to the start of the sequence
-
replay_webhook_deliveryExecuteReplay a previous webhook delivery, re-sending the same event payload to the endpoint.
-
restart_ab_testExecuteRun another sequence A/B test after a winner is selected. By default the winner becomes the new control; pass sourceVariantId to use another variant as the control email.
-
resume_campaignExecuteResume a paused campaign. Only campaigns in paused status can be resumed. Optionally spread the remaining delivery over a number of hours.
-
resume_sendingExecuteRequest that paused company-level sending be restored after fixing the cause. This is the supported remediation path for an account paused by the permanent-bounce rate limit - i...
-
schedule_campaignExecuteSchedule a draft or already scheduled campaign as a one-off send or on a repeating weekly/monthly cadence via
-
send_sequence_test_emailExecuteQueue a real test send for one saved action_email step in a sequence. Call get_sequence first and pass the target sequence.emails entry
-
send_test_emailExecuteQueue a campaign test email to a single address. Returns a durable emailSendId; pass it to get_email_send for delivery status and failure details.
-
send_test_smsExecuteSend a test SMS to a phone number. IMPORTANT: sends a real text message and charges SMS credits - only call when the user explicitly asks for a test send. Requires the SMS add-o...
-
sync_audience_nowExecuteTrigger an immediate upload of the segment
-
sync_integrationExecuteQueue a manual re-sync for an integration: customers and revenue for a payment provider (Stripe, Polar, Paddle, Dodo, Creem, Chargebee, Whop), the user backfill for Supabase, or...
-
sync_productsExecuteQueue a sync of the Stripe product catalog into the products list. Requires an active Stripe integration with bulk sync enabled. Pass integrationId when more than one Stripe acc...
-
test_webhookExecuteSend a test event to an outbound webhook endpoint to verify it is reachable and signatures can be validated.
-
trigger_subscriber_eventExecuteEmit a custom event for one subscriber, exactly as an integration or the public API would. This is the supported way to exercise event triggers, matching-field idempotency, bran...
-
trigger_subscriber_eventsExecuteEmit several custom events for one subscriber in order. Events are processed independently and sequentially, so a partial failure can still leave earlier events recorded.
-
verify_sending_domainExecuteRun a fresh DNS check for a configured sending domain and return DNS verification separately from sending readiness. A DNS-verified domain may still be activating; when readyToS...
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.