gluecron_propose_migration
Propose a dependency-upgrade PR. Wraps src/lib/migration-assistant.proposeMajorMigration. Requires 'repo' scope.
This record as markdown: /tools/com-gluecron-gluecron/gluecron-propose-migration.md
What gluecron_propose_migration does on Gluecron
AI agents use gluecron_propose_migration to create or update resources in Gluecron, usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your Gluecron environment.
| Parameter | Type | Required | Description |
|---|---|---|---|
repo | string | Yes | |
owner | string | Yes | |
base_sha | string | Yes | Commit sha to fork from |
changelog | string | — | Optional changelog text |
dependency | string | Yes | |
to_version | string | Yes | |
from_version | string | Yes |
Parameters from the server's own tool schema.
Why gluecron_propose_migration is rated Medium
This tool creates (writes) a PR suggesting dependency upgrades. PRs are reversible—they can be closed or reverted—so this is Write rather than Execute or Destructive. The severity is medium because a malicious agent could propose problematic migrations that create noise or introduce vulnerabilities, but the PR still requires review/approval before merging.
From the tool's definition 'Propose a dependency-upgrade PR' creates a new pull request, which is a reversible modification to repository state. The tool wraps proposeMajorMigration and operates within git hosting infrastructure.
Attacks that exploit this kind of access
The rule that runs gluecron_propose_migration safely
PolicyLayer is an MCP gateway: it sits between your AI agents and Gluecron, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For gluecron_propose_migration, this is the rule to start with:
gluecron_propose_migration stays usable, but capped: an agent stuck in a loop can't make hundreds of changes a minute. Everything else on the server is denied unless you say otherwise.
The button opens the PolicyLayer dashboard: create your workspace, connect Gluecron, apply this rule, and every gluecron_propose_migration call is checked against it from then on.
Questions about gluecron_propose_migration
Propose a dependency-upgrade PR. Wraps src/lib/migration-assistant.proposeMajorMigration. Requires 'repo' scope. It is categorised as a Write tool in the Gluecron MCP Server, which means it can create or modify data. Consider rate limits to prevent runaway writes.
gluecron_propose_migration accepts 7 parameters: repo, owner, base_sha, changelog, dependency, to_version, from_version. Required: repo, owner, base_sha, dependency, to_version, from_version. The full parameter table on this page comes from the server's own tool schema.
Register the Gluecron MCP server in PolicyLayer and add a rule for gluecron_propose_migration: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches Gluecron. Nothing to install.
gluecron_propose_migration is a Write tool with medium risk. Write tools should be rate-limited to prevent accidental bulk modifications.
Yes. Add a rate_limit block to the gluecron_propose_migration rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for gluecron_propose_migration. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
gluecron_propose_migration is provided by the Gluecron MCP server (https://gluecron.com/mcp). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on Gluecron, and thousands of servers like it.
This server
Across the catalogue