High-risk tools in Telephony MCP Server
3 of the 5 tools in Telephony MCP Server are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
sms_with_inputExecuteSend an SMS to a recipient and wait for an event at {CALLBACK_SERVER_URL}/event. When an event arrives for the same msisdn, display the text and stop waiting. Uses the Vonage SM...
-
voice_callExecuteMake a voice call or phone call to a given number. Accepts prompts like
-
voice_call_with_inputExecuteMake a voice call to a given number and wait for speech input from the recipient. Accepts prompts like
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.