This record as markdown: /tools/0xyubo-ripple-mcp/trace-callers.md
What trace_callers does on Ripple-MCP
AI agents call trace_callers to retrieve information from Ripple-MCP without modifying anything. It is typically the context-gathering step in research, monitoring, and reporting workflows, before the agent takes action elsewhere.
Why trace_callers is rated Low
The tool is purely analytical: it traverses the call graph to identify callers of a function at various depths (depth=1 for direct callers). This is equivalent to a 'find' or 'search' operation on code structure, with no side effects. It retrieves call relationship data without altering code, executing arbitrary commands, or destroying data.
From the tool's definition Tool performs 'BFS 逐层找出调用指定函数的函数' (breadth-first search to find functions that call a specified function). This is a query/analysis operation that traces call relationships without modifying, executing, or deleting any code.
Attacks that exploit this kind of access
The rule that runs trace_callers safely
PolicyLayer is an MCP gateway: it sits between your AI agents and Ripple-MCP, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For trace_callers, this is the rule to start with:
trace_callers is read-only, so it stays allowed. Everything else on the server is denied unless you say otherwise.
The button opens the PolicyLayer dashboard: create your workspace, connect Ripple-MCP, apply this rule, and every trace_callers call is checked against it from then on.
Questions about trace_callers
BFS 逐层找出调用指定函数的函数:depth=1 为直接调用者,. It is categorised as a Read tool in the Ripple-MCP MCP Server, which means it retrieves data without modifying state.
Register the Ripple MCP server in PolicyLayer and add a rule for trace_callers: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches Ripple-MCP. Nothing to install.
trace_callers is a Read tool with low risk. Read-only tools are generally safe to allow by default.
Yes. Add a rate_limit block to the trace_callers rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for trace_callers. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
trace_callers is provided by the Ripple MCP server (0xyubo/ripple-mcp). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on Ripple, and thousands of servers like it.
This server
Across the catalogue