# hires_upload_attachment

Upload a file and create an attachment. Supported categories: voicemail (wav/mp3, max 20 MB, no object_id — returned uuid is usable as attachment_uuid in nurture voicemail steps); candidate (candidate ID); application (application ID); candidate_comment (comment ID); job_note (job-note ID); company_favicon/company_header/company_link_preview (company ID). Object ownership is strictly verified against the authenticated API key's company. Returns {uuid, url, file, relative_time}.

Agent View of the PolicyLayer registry record for `hires_upload_attachment`. HTML page: https://policylayer.com/tools/com-100hires-100hires/hires-upload-attachment

## Facts

- Tool: `hires_upload_attachment`
- Server: 100Hires - AI ATS & Recruitment Software (`https://mcp.100hires.com/mcp`) — https://policylayer.com/tools/com-100hires-100hires.md
- Homepage: https://github.com/100Hires/mcp
- Risk category: Write (Medium risk)
- Registry record: grade F, identity unverified
- Server auth posture: open
- Server rate-limited: no
- Parameters: 4 (2 required)
- Recommended policy verdict: Rate-limited

## Parameters

| Parameter | Type | Required | Description |
| --- | --- | --- | --- |
| `file` | object | yes | File payload. |
| `category` | string | yes | Attachment category. Determines allowed extensions and object_id semantics. |
| `object_id` | number | null | no | Target object ID (candidate/application/comment/job-note/company, per category). Omit for `voicemail`. |
| `company_id` | number | null | no | Target company ID. Needed for partner API keys managing multiple client companies. Omitted → defaults to the authenticated company. The object_id must belong to |

Parameters from the server's own tool schema.

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "hires_upload_attachment",
    "arguments": {
      "file": {},
      "category": "<category>"
    }
  }
}
```

## Why hires_upload_attachment is rated Medium

This tool creates new attachment records in the system, which is a reversible data modification operation. It does not execute code, delete data, or move money. The 'medium' severity reflects that file uploads could potentially be abused to store malicious content or exhaust storage quotas, but the strict object ownership verification and file type/size constraints (max 20 MB for audio) mitigate risk.

From the tool's own definition: "Tool description states 'Upload a file and create an attachment' with support for multiple object types (candidate, application, comment, job note, company assets). Returns uuid, url, file, and relative_time indicating persistent creation of new resources."

Risk signals: Accepts file system path (file)

## Use case

AI agents use hires_upload_attachment to create or update resources in 100Hires - AI ATS & Recruitment Software, usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your 100Hires - AI ATS & Recruitment Software environment.

## Recommended policy (PolicyLayer)

Verdict: **Rate-limited**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches 100Hires - AI ATS & Recruitment Software:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "hires_upload_attachment": {
      "limits": [
        {
          "counter": "hires_upload_attachment_rate",
          "window": "minute",
          "max": 30,
          "scope": "grant"
        }
      ]
    }
  }
}
```

## Other tools on 100Hires - AI ATS & Recruitment Software (132)

- `hires_batch_remove_from_boards` — Destructive — https://policylayer.com/tools/com-100hires-100hires/hires-batch-remove-from-boards.md
- `hires_cancel_all_notification_messages` — Destructive — https://policylayer.com/tools/com-100hires-100hires/hires-cancel-all-notification-messages.md
- `hires_delete_application` — Destructive — https://policylayer.com/tools/com-100hires-100hires/hires-delete-application.md
- `hires_delete_candidate` — Destructive — https://policylayer.com/tools/com-100hires-100hires/hires-delete-candidate.md
- `hires_delete_company` — Destructive — https://policylayer.com/tools/com-100hires-100hires/hires-delete-company.md
- `hires_delete_email_template` — Destructive — https://policylayer.com/tools/com-100hires-100hires/hires-delete-email-template.md
- `hires_delete_form` — Destructive — https://policylayer.com/tools/com-100hires-100hires/hires-delete-form.md
- `hires_delete_job` — Destructive — https://policylayer.com/tools/com-100hires-100hires/hires-delete-job.md
- `hires_delete_job_webhook` — Destructive — https://policylayer.com/tools/com-100hires-100hires/hires-delete-job-webhook.md
- `hires_delete_message` — Destructive — https://policylayer.com/tools/com-100hires-100hires/hires-delete-message.md
- `hires_delete_note` — Destructive — https://policylayer.com/tools/com-100hires-100hires/hires-delete-note.md
- `hires_delete_notification_message` — Destructive — https://policylayer.com/tools/com-100hires-100hires/hires-delete-notification-message.md
- `hires_delete_nurture_campaign` — Destructive — https://policylayer.com/tools/com-100hires-100hires/hires-delete-nurture-campaign.md
- `hires_delete_question` — Destructive — https://policylayer.com/tools/com-100hires-100hires/hires-delete-question.md
- `hires_delete_webhook` — Destructive — https://policylayer.com/tools/com-100hires-100hires/hires-delete-webhook.md
- `hires_disqualify_candidate` — Destructive — https://policylayer.com/tools/com-100hires-100hires/hires-disqualify-candidate.md
- `hires_remove_from_job_board` — Destructive — https://policylayer.com/tools/com-100hires-100hires/hires-remove-from-job-board.md
- `hires_batch_job_boards` — Read — https://policylayer.com/tools/com-100hires-100hires/hires-batch-job-boards.md
- `hires_download_attachment` — Read — https://policylayer.com/tools/com-100hires-100hires/hires-download-attachment.md
- `hires_get_ai_score` — Read — https://policylayer.com/tools/com-100hires-100hires/hires-get-ai-score.md
- `hires_get_application` — Read — https://policylayer.com/tools/com-100hires-100hires/hires-get-application.md
- `hires_get_billing` — Read — https://policylayer.com/tools/com-100hires-100hires/hires-get-billing.md
- `hires_get_candidate` — Read — https://policylayer.com/tools/com-100hires-100hires/hires-get-candidate.md
- `hires_get_candidate_resume` — Read — https://policylayer.com/tools/com-100hires-100hires/hires-get-candidate-resume.md
- `hires_get_career_job` — Read — https://policylayer.com/tools/com-100hires-100hires/hires-get-career-job.md
- `hires_get_company` — Read — https://policylayer.com/tools/com-100hires-100hires/hires-get-company.md
- `hires_get_email_template` — Read — https://policylayer.com/tools/com-100hires-100hires/hires-get-email-template.md
- `hires_get_evaluation` — Read — https://policylayer.com/tools/com-100hires-100hires/hires-get-evaluation.md
- `hires_get_form` — Read — https://policylayer.com/tools/com-100hires-100hires/hires-get-form.md
- `hires_get_interview` — Read — https://policylayer.com/tools/com-100hires-100hires/hires-get-interview.md
- …and 102 more: https://policylayer.com/tools/com-100hires-100hires.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=com-100hires-100hires · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/com-100hires-100hires
