Critical Risk →

remove_breakpoints

remove_breakpoints

How to control remove_breakpoints ↓

AI agents call remove_breakpoints to permanently remove resources in MiniApp CDP MCP — typically in cleanup and lifecycle workflows. It does its job in a single call, and there is no undo.

Critical Risk

The tool name strongly suggests it removes/deletes breakpoints set in the debugger. Removing breakpoints is a destructive action in the context of a debugging session — it cannot be trivially undone if the original breakpoint configuration is lost. However, since the description is empty, confidence is reduced.

From the tool's definition Tool name 'remove_breakpoints' implies deletion of breakpoints; description is empty and uninformative

Documented attack patterns abuse exactly the kind of access remove_breakpoints gives an agent:

PolicyLayer is an MCP gateway — it sits between your AI agents and MiniApp CDP MCP, and nothing reaches the server without passing your rules. This is the rule we recommend for remove_breakpoints:

policy.json
{
  "version": "1",
  "default": "deny",
  "hide": [
    "remove_breakpoints"
  ]
}

remove_breakpoints disappears from the agent's tool list entirely, and any attempt to call it is denied. The rest of the server keeps working.

  1. Create a free account and register MiniApp CDP MCP — nothing to install.
  2. Add this policy — paste it, or build it visually.
  3. Point your MCP client (Claude, Cursor, anything) at your gateway URL.
RESTRICT THIS TOOL →

Free to start. No card required.

Go deeper

What does the remove_breakpoints tool do? +

remove_breakpoints. It is categorised as a Destructive tool in the MiniApp CDP MCP MCP Server, which means it can permanently delete or destroy data. Block by default and require explicit approval.

How do I enforce a policy on remove_breakpoints? +

Register the MiniApp CDP MCP server in PolicyLayer and add a rule for remove_breakpoints: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches MiniApp CDP MCP. Nothing to install.

What risk level is remove_breakpoints? +

remove_breakpoints is a Destructive tool with critical risk. Critical-risk tools should be blocked by default and only enabled with explicit human approval.

Can I rate-limit remove_breakpoints? +

Yes. Add a rate_limit block to the remove_breakpoints rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.

How do I block remove_breakpoints completely? +

Set action: deny in the PolicyLayer policy for remove_breakpoints. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.

What MCP server provides remove_breakpoints? +

remove_breakpoints is provided by the MiniApp CDP MCP server (zhizhuodemao/miniapp-cdp-mcp). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.

Enforce policy on every MiniApp CDP MCP tool call.

Deterministic rules across all 18 MiniApp CDP MCP tools. Per-identity grants. Full audit log. Live in minutes. Nothing to install.

Free to start. No card required.

18 MiniApp CDP MCP tools catalogued and risk-classified — across an index of 42,500+ MCP servers.

// GET IN TOUCH

Have a question or want to learn more? Send us a message.

Message sent.

We'll get back to you soon.