# submit_asset_from_url

Submit a .glb hosted at a public https URL on the user’s behalf (requires their API key). We download it, validate and re-encode it, then a human reviews it before publishing. CC0 is automatic, but the user must accept its irrevocable dedication before submission. Max 25 MB, 1M triangles, embedded textures only.

Agent View of the PolicyLayer registry record for `submit_asset_from_url`. HTML page: https://policylayer.com/tools/3dassets-mcp/submit-asset-from-url

## Facts

- Tool: `submit_asset_from_url`
- Server: 3dassets (`3dassets-mcp`) — https://policylayer.com/tools/3dassets-mcp.md
- Install: `npx -y 3dassets-mcp`
- Homepage: https://www.npmjs.com/package/3dassets-mcp
- Risk category: Write (Medium risk)
- Registry record: grade F, identity unverified
- Server rate-limited: no
- Parameters: 11 (5 required)
- Recommended policy verdict: Rate-limited

## Parameters

| Parameter | Type | Required | Description |
| --- | --- | --- | --- |
| `url` | string | yes |  |
| `tags` | array | no |  |
| `title` | string | yes |  |
| `aiModel` | string | no | Contributor-reported model ID or custom model/tool name; use list_ai_models for suggestions. Omit if unknown. |
| `license` | string | no | Fixed CC0 1.0 Universal dedication; no licence selection |
| `summary` | string | yes | Plain 1–2 sentence description |
| `category` | string | yes | From list_categories |
| `sourceUrl` | string | no | Where the original was first published |
| `aiGenerated` | boolean | no | AI helped create geometry, code or textures; not merely uploading |
| `attestation` | boolean | yes | Required contributor acceptance (including for agent submissions): I confirm that I created this asset or hold the rights to publish it under CC0 1.0 Universal, |
| `description` | string | no | Markdown: scale, pivot, what is included |

Parameters from the server's own tool schema.

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "submit_asset_from_url",
    "arguments": {
      "url": "<url>",
      "title": "<title>",
      "summary": "<summary>",
      "category": "<category>",
      "attestation": false
    }
  }
}
```

## Why submit_asset_from_url is rated Medium

An AI agent can call submit_asset_from_url faster than any human can review: one bad instruction and it creates or modifies resources in 3dassets by the hundred, each call as confident as the last.

Risk signals: Accepts URL/endpoint input (url) · High parameter count (11 properties)

## Use case

AI agents use submit_asset_from_url to create or update resources in 3dassets, usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your 3dassets environment.

## Recommended policy (PolicyLayer)

Verdict: **Rate-limited**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches 3dassets:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "submit_asset_from_url": {
      "limits": [
        {
          "counter": "submit_asset_from_url_rate",
          "window": "minute",
          "max": 30,
          "scope": "grant"
        }
      ]
    }
  }
}
```

## Other tools on 3dassets (19)

- `finalize_upload` — Financial — https://policylayer.com/tools/3dassets-mcp/finalize-upload.md
- `get_asset` — Read — https://policylayer.com/tools/3dassets-mcp/get-asset.md
- `get_asset_usage` — Read — https://policylayer.com/tools/3dassets-mcp/get-asset-usage.md
- `get_demo` — Read — https://policylayer.com/tools/3dassets-mcp/get-demo.md
- `get_pack` — Read — https://policylayer.com/tools/3dassets-mcp/get-pack.md
- `get_upload_url` — Read — https://policylayer.com/tools/3dassets-mcp/get-upload-url.md
- `list_ai_models` — Read — https://policylayer.com/tools/3dassets-mcp/list-ai-models.md
- `list_categories` — Read — https://policylayer.com/tools/3dassets-mcp/list-categories.md
- `list_demos` — Read — https://policylayer.com/tools/3dassets-mcp/list-demos.md
- `list_licenses` — Read — https://policylayer.com/tools/3dassets-mcp/list-licenses.md
- `list_tags` — Read — https://policylayer.com/tools/3dassets-mcp/list-tags.md
- `my_assets` — Read — https://policylayer.com/tools/3dassets-mcp/my-assets.md
- `my_packs` — Read — https://policylayer.com/tools/3dassets-mcp/my-packs.md
- `search_assets` — Read — https://policylayer.com/tools/3dassets-mcp/search-assets.md
- `search_packs` — Read — https://policylayer.com/tools/3dassets-mcp/search-packs.md
- `verify_account` — Read — https://policylayer.com/tools/3dassets-mcp/verify-account.md
- `create_account` — Write — https://policylayer.com/tools/3dassets-mcp/create-account.md
- `submit_pack` — Write — https://policylayer.com/tools/3dassets-mcp/submit-pack.md
- `update_asset` — Write — https://policylayer.com/tools/3dassets-mcp/update-asset.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=3dassets-mcp · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/3dassets-mcp
