High-risk tools in SmartBear MCP
10 of the 240 tools in SmartBear MCP are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
collaborator_reviewservice_actionExecuteInvoke any ReviewService method by name and arguments. For finishReviewPhase and waitOnPhase, provide reviewId (required) and until (optional, defaults to 'ANY'). **Parameters:...
-
collaborator_test_collaborator_remote_system_configuration_connectionExecuteTests the connection for a remote system configuration in Collaborator by its ID. **Parameters:** - id (union) *required*: ID of the remote system Configuration to test connect...
-
contract-testing_execute_webhookExecuteTrigger a test execution of a specific webhook. **Parameters:** - webhookId (string) *required*: UUID of the webhook
-
contract-testing_generate_pact_testsExecuteGenerate Pact tests using PactFlow AI. You can provide one or more of the following input types: (1) request/response pairs for specific interactions, (2) code files to analyze ...
-
contract-testing_review_pact_testsExecuteReview Pact tests using PactFlow AI. You can provide the following inputs: (1) Pact tests to be reviewed along with metadata **Parameters:** - pactTests (object) *required*: Pr...
-
contract-testing_test_execute_webhooksExecuteTrigger a test execution of all matching webhooks without a real event. **Parameters:**
-
reflect_add_prompt_stepExecuteAdd a natural language prompt step to an active Reflect recording session **Parameters:** - sessionId (string) *required*: The ID of the Reflect recording session - prompt (str...
-
reflect_connect_to_sessionExecuteConnect to an active Reflect recording session via WebSocket to enable interactive control. When creating or editing a Reflect test using a connected recording session, follow t...
-
reflect_execute_suiteExecuteExecute a reflect suite **Parameters:** - suiteId (string) *required*: ID of the reflect suite to execute
-
reflect_run_testExecuteRun a reflect test **Parameters:** - testId (string) *required*: ID of the reflect test to run
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.