# hash_random_field

Get random field(s) from hash. Args: key: The name of the key count: Number of fields to return (optional) Returns: Random field(s) or error message

Agent View of the PolicyLayer registry record for `hash_random_field`. HTML page: https://policylayer.com/tools/aws/hash-random-field

## Facts

- Tool: `hash_random_field`
- Server: AWS (`@awslabs/mcp`) — https://policylayer.com/tools/aws.md
- Install: `npx -y @awslabs/mcp`
- Homepage: https://github.com/awslabs/mcp
- Risk category: Read (Low risk)
- Registry record: grade F, identity verified
- Server rate-limited: no
- Parameters: 0
- Recommended policy verdict: Allowed

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "hash_random_field",
    "arguments": {}
  }
}
```

## Why hash_random_field is rated Low

This is a read operation that queries data from a hash structure. No data is created, modified, deleted, or executed. The operation is purely informational with no side effects. Low severity because misuse would only expose potentially sensitive hash contents, not cause irreversible harm or external effects.

From the tool's own definition: "Tool returns random field(s) from a hash with no modification capability. Description states 'Get random field(s)' indicating a retrieval operation. Arguments are read-only (key name and count), with no destructive or mutating operations possible."

## Use case

AI agents call hash_random_field to retrieve information from AWS without modifying anything. It is typically the context-gathering step in research, monitoring, and reporting workflows, before the agent takes action elsewhere.

## Recommended policy (PolicyLayer)

Verdict: **Allowed**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches AWS:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "hash_random_field": {}
  }
}
```

## Other tools on AWS (299)

- `bulk_delete_by_criteria` — Destructive — https://policylayer.com/tools/aws/bulk-delete-by-criteria.md
- `cache_delete` — Destructive — https://policylayer.com/tools/aws/cache-delete.md
- `cache_delete_many` — Destructive — https://policylayer.com/tools/aws/cache-delete-many.md
- `cache_delete_multi` — Destructive — https://policylayer.com/tools/aws/cache-delete-multi.md
- `cache_flush_all` — Destructive — https://policylayer.com/tools/aws/cache-flush-all.md
- `delete` — Destructive — https://policylayer.com/tools/aws/delete.md
- `delete_access_key` — Destructive — https://policylayer.com/tools/aws/delete-access-key.md
- `delete_datastore` — Destructive — https://policylayer.com/tools/aws/delete-datastore.md
- `delete_group` — Destructive — https://policylayer.com/tools/aws/delete-group.md
- `delete_image_set` — Destructive — https://policylayer.com/tools/aws/delete-image-set.md
- `delete_instance_in_series` — Destructive — https://policylayer.com/tools/aws/delete-instance-in-series.md
- `delete_instance_in_study` — Destructive — https://policylayer.com/tools/aws/delete-instance-in-study.md
- `delete_patient_studies` — Destructive — https://policylayer.com/tools/aws/delete-patient-studies.md
- `delete_resource` — Destructive — https://policylayer.com/tools/aws/delete-resource.md
- `delete_role_policy` — Destructive — https://policylayer.com/tools/aws/delete-role-policy.md
- `delete_series_by_uid` — Destructive — https://policylayer.com/tools/aws/delete-series-by-uid.md
- `delete_study` — Destructive — https://policylayer.com/tools/aws/delete-study.md
- `delete_user` — Destructive — https://policylayer.com/tools/aws/delete-user.md
- `delete_user_policy` — Destructive — https://policylayer.com/tools/aws/delete-user-policy.md
- `detach_user_policy` — Destructive — https://policylayer.com/tools/aws/detach-user-policy.md
- `json_arrtrim` — Destructive — https://policylayer.com/tools/aws/json-arrtrim.md
- `json_clear` — Destructive — https://policylayer.com/tools/aws/json-clear.md
- `json_del` — Destructive — https://policylayer.com/tools/aws/json-del.md
- `list_pop_left` — Destructive — https://policylayer.com/tools/aws/list-pop-left.md
- `list_trim` — Destructive — https://policylayer.com/tools/aws/list-trim.md
- `remove_instance_from_image_set` — Destructive — https://policylayer.com/tools/aws/remove-instance-from-image-set.md
- `remove_series_from_image_set` — Destructive — https://policylayer.com/tools/aws/remove-series-from-image-set.md
- `set_pop` — Destructive — https://policylayer.com/tools/aws/set-pop.md
- `sorted_set_remove_by_lex` — Destructive — https://policylayer.com/tools/aws/sorted-set-remove-by-lex.md
- `sorted_set_remove_by_score` — Destructive — https://policylayer.com/tools/aws/sorted-set-remove-by-score.md
- …and 269 more: https://policylayer.com/tools/aws.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=aws · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/aws
