High-risk tools in Samarth Gtm Mcp
9 of the 236 tools in Samarth Gtm Mcp are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
consent_compliance_auditExecuteRun the full audit agent against a website: crawls same-site pages, inventories forms,
-
consent_scenario_captureExecuteLoad a page under one consent scenario and capture the evidence:
-
environments_reauthorizeExecute[PUBLISH] Re-generate the authorization code for a GTM environment.
-
run_ga4_reportExecuteRun a GA4 report. dimensions/metrics are GA4 API names (e.g. [
-
runtime_synthetic_testExecuteRUNTIME synthetic test (READ-ONLY, SAFE): load a live URL in headless Chromium, push SYNTHETIC dataLayer funnel events with obviously-fake values, and capture the analytics /col...
-
site_crawlExecuteCrawl a website starting from a URL (same-site BFS, form-heavy pages prioritised).
-
suggest_tags_from_urlExecuteScan a LIVE web page with a headless browser and return the GA4 event tags worth creating for it, INCLUDING the exact TRIGGER CONDITION each needs: form submits scoped by Form I...
-
versions_publishExecute[PUBLISH] Publish a specific GTM container version to live.
-
workspace_create_version_and_publishExecute[PUBLISH] Create a new container version from a workspace and immediately publish it.
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.