derive_from_website
SPIKE tool (.agent/design-docs/2026-07-09-magical-onboarding-buildout-mode.md, "The Assignment"). Give it a business's public URL; it reads the page and returns a derived ICP, a derived brand voice, and 3 ready-to-post drafts written in that voice — the onboarding lead magnet's engine, spike-grad...
This record as markdown: /tools/com-getfreedomos-freedom-mcp/derive-from-website.md
What derive_from_website does on Freedom Mcp
AI agents call derive_from_website to retrieve information from Freedom Mcp without modifying anything. It is typically the context-gathering step in research, monitoring, and reporting workflows, before the agent takes action elsewhere.
| Parameter | Type | Required | Description |
|---|---|---|---|
url | string | Yes | The business's public URL to derive from (must include https:// or http://) — their homepage or an About/product page. |
companyId | string | — | FreedomOS company id to act within (you must be a member). Required for company-scoped tools. |
Parameters from the server's own tool schema.
Why derive_from_website is rated Low
Fetches and analyzes a public URL; no data is written or persisted anywhere.
From the tool's definition reads the page and returns a derived ICP... Nothing is persisted
Risk signalsAccepts URL/endpoint input (url)
Attacks that exploit this kind of access
The rule that runs derive_from_website safely
PolicyLayer is an MCP gateway: it sits between your AI agents and Freedom Mcp, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For derive_from_website, this is the rule to start with:
derive_from_website is read-only, so it stays allowed. Everything else on the server is denied unless you say otherwise.
The button opens the PolicyLayer dashboard: create your workspace, connect Freedom Mcp, apply this rule, and every derive_from_website call is checked against it from then on.
Questions about derive_from_website
SPIKE tool (.agent/design-docs/2026-07-09-magical-onboarding-buildout-mode.md, "The Assignment"). Give it a business's public URL; it reads the page and returns a derived ICP, a derived brand voice, and 3 ready-to-post drafts written in that voice — the onboarding lead magnet's engine, spike-grade. Nothing is persisted to any company. Use when your operator asks you to run the website-derivation spike against a real business URL, to show the operator what an agent team can already see about their business. [sensitive-tier — first use may require a manager's approval; a from-now-on approval makes future calls seamless, a just-once approval re-asks next time.]. It is categorised as a Read tool in the Freedom Mcp MCP Server, which means it retrieves data without modifying state.
derive_from_website accepts 2 parameters: url, companyId. Required: url. The full parameter table on this page comes from the server's own tool schema.
Register the Freedom MCP server in PolicyLayer and add a rule for derive_from_website: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches Freedom Mcp. Nothing to install.
derive_from_website is a Read tool with low risk. Read-only tools are generally safe to allow by default.
Yes. Add a rate_limit block to the derive_from_website rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for derive_from_website. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
derive_from_website is provided by the Freedom MCP server (https://twuluxmoognlwtmaoqgo.supabase.co/functions/v1/freedom-mcp). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on Freedom, and thousands of servers like it.
This server
Across the catalogue