# upload_design_md

Uploads DESIGN.md to a Stitch project. Use this tool when the user wants to create a design system from a DESIGN.md file. Instructions for Tool Call: * Call create_design_system_from_design_md tool immediately after this tool to create the design system from the uploaded DESIGN.md, and display the design system in the UI.

Agent View of the PolicyLayer registry record for `upload_design_md`. HTML page: https://policylayer.com/tools/com-googleapis-stitch-mcp/upload-design-md

## Facts

- Tool: `upload_design_md`
- Server: Mcp (`https://stitch.googleapis.com/mcp`) — https://policylayer.com/tools/com-googleapis-stitch-mcp.md
- Homepage: https://github.com/https://stitch.googleapis.com/mcp
- Risk category: Write (Medium risk)
- Registry record: grade D, identity unverified
- Server auth posture: open
- Server rate-limited: no
- Parameters: 2 (2 required)
- Recommended policy verdict: Rate-limited

## Parameters

| Parameter | Type | Required | Description |
| --- | --- | --- | --- |
| `projectId` | string | yes | Required. The project ID to upload the DESIGN.md to, example: '4044680601076201931', without the `projects/` prefix. |
| `designMdBase64` | string | yes | Required. The base64-encoded DESIGN.md content. The decoded content must be valid UTF-8; uploads with invalid UTF-8 bytes will be rejected. Run `base64 -w 0 ` t |

Parameters from the server's own tool schema.

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "upload_design_md",
    "arguments": {
      "projectId": "<projectId>",
      "designMdBase64": "<designMdBase64>"
    }
  }
}
```

## Why upload_design_md is rated Medium

The tool performs a write operation by uploading a file to a project. It is reversible (can be deleted or overwritten) and does not delete data or execute arbitrary code. The severity is low because design system files are typically configuration/documentation artifacts with limited blast radius if misused—the worst case would be overwriting a design system definition, which is recoverable.

From the tool's own definition: "Uploads DESIGN.md to a Stitch project. This is a file upload operation that creates or modifies project data (the DESIGN.md file within the project)."

## Use case

AI agents use upload_design_md to create or update resources in Mcp, usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your Mcp environment.

## Recommended policy (PolicyLayer)

Verdict: **Rate-limited**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Mcp:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "upload_design_md": {
      "limits": [
        {
          "counter": "upload_design_md_rate",
          "window": "minute",
          "max": 30,
          "scope": "grant"
        }
      ]
    }
  }
}
```

## Other tools on Mcp (14)

- `delete_project` — Destructive — https://policylayer.com/tools/com-googleapis-stitch-mcp/delete-project.md
- `get_project` — Read — https://policylayer.com/tools/com-googleapis-stitch-mcp/get-project.md
- `get_screen` — Read — https://policylayer.com/tools/com-googleapis-stitch-mcp/get-screen.md
- `list_design_systems` — Read — https://policylayer.com/tools/com-googleapis-stitch-mcp/list-design-systems.md
- `list_projects` — Read — https://policylayer.com/tools/com-googleapis-stitch-mcp/list-projects.md
- `list_screens` — Read — https://policylayer.com/tools/com-googleapis-stitch-mcp/list-screens.md
- `apply_design_system` — Write — https://policylayer.com/tools/com-googleapis-stitch-mcp/apply-design-system.md
- `create_design_system` — Write — https://policylayer.com/tools/com-googleapis-stitch-mcp/create-design-system.md
- `create_design_system_from_design_md` — Write — https://policylayer.com/tools/com-googleapis-stitch-mcp/create-design-system-from-design-md.md
- `create_project` — Write — https://policylayer.com/tools/com-googleapis-stitch-mcp/create-project.md
- `edit_screens` — Write — https://policylayer.com/tools/com-googleapis-stitch-mcp/edit-screens.md
- `generate_screen_from_text` — Write — https://policylayer.com/tools/com-googleapis-stitch-mcp/generate-screen-from-text.md
- `generate_variants` — Write — https://policylayer.com/tools/com-googleapis-stitch-mcp/generate-variants.md
- `update_design_system` — Write — https://policylayer.com/tools/com-googleapis-stitch-mcp/update-design-system.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=com-googleapis-stitch-mcp · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/com-googleapis-stitch-mcp
