High-risk tools in UniFi Access MCP
29 of the 272 tools in UniFi Access MCP are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
access_lock_doorExecuteaccess_lock_door
-
access_reboot_deviceExecuteaccess_reboot_device
-
access_unlock_doorExecuteaccess_unlock_door
-
protect_ptz_moveExecuteprotect_ptz_move
-
protect_ptz_presetExecuteprotect_ptz_preset
-
protect_reboot_cameraExecuteprotect_reboot_camera
-
protect_trigger_chimeExecuteprotect_trigger_chime
-
unifi_batchExecuteExecute multiple UniFi tools in a single request. Each call is an object with
-
unifi_block_clientExecuteBlock a client/device from the network by MAC address
-
unifi_configure_port_aggregationExecuteConfigure link aggregation (LACP/LAG) on a switch. Bonds consecutive ports
-
unifi_configure_port_mirrorExecuteConfigure port mirroring on a switch. Mirrors traffic from one port to a
-
unifi_executeExecuteExecute a UniFi tool by name. Use unifi_tool_index to discover available tools first.
-
unifi_force_provision_deviceExecuteForce re-provision a device, pushing the current configuration from the
-
unifi_force_reconnect_clientExecuteForce a client to reconnect to the network (kick) by MAC address
-
unifi_locate_deviceExecuteToggle device locate mode (LED blinking) to physically identify a device.
-
unifi_power_cycle_portExecutePower cycle PoE on a specific switch port. This briefly cuts power to the
-
unifi_reboot_deviceExecuteReboot a specific device by MAC address
-
unifi_reorder_firewall_policiesExecuteunifi_reorder_firewall_policies
-
unifi_set_outlet_stateExecuteunifi_set_outlet_state
-
unifi_toggle_deviceExecuteunifi_toggle_device
-
unifi_toggle_firewall_policyExecuteEnable or disable a specific firewall policy by ID.
-
unifi_toggle_port_forwardExecuteToggle a port forwarding rule on or off on your Unifi Network controller.
-
unifi_toggle_traffic_routeExecuteToggle a traffic route on/off by ID.
-
unifi_toggle_wlanExecuteToggle a WLAN/SSID on or off. Requires confirmation.
-
unifi_trigger_rf_scanExecuteunifi_trigger_rf_scan
-
unifi_trigger_speedtestExecuteTrigger a speedtest on the gateway device. Returns immediately;
-
unifi_update_vpn_client_stateExecuteEnable or disable a specific VPN client by ID.
-
unifi_update_vpn_server_stateExecuteEnable or disable a specific VPN server by ID.
-
unifi_upgrade_deviceExecuteInitiate a firmware upgrade for a device by MAC address (uses cached firmware by default)
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.