toolx
ToolX runtime — load and execute PromptX ecosystem tools What It Does Universal interface for calling PromptX tools (file ops, PDF reading, role creation, etc.). Input is a YAML document specifying the tool, mode, and parameters. Modes | Mode | Purpose | |---|---| | manual | Read tool documentati...
This record as markdown: /tools/deepractice-promptx/toolx.md
What toolx does on PromptX
AI agents invoke toolx to trigger actions in PromptX. What it does depends on the arguments the agent supplies, and its effects often reach beyond the immediate call: builds kicked off, notifications sent, workflows started.
Why toolx is rated High
toolx is a meta-tool that executes other PromptX tools based on YAML input. While it includes safe modes (manual, log, dryrun), the execute mode runs arbitrary tools from the ecosystem with user-specified parameters. The sibling tools span Read, Write, and Destructive categories; toolx's capacity to invoke them means misuse could delete workspaces, modify files, or execute code.
From the tool's definition "Universal interface for calling PromptX tools" with 'execute' mode to "Run the tool with parameters"; ecosystem includes destructive tools (delete_workspace_item) and file operations; YAML-based arbitrary tool invocation enables execution of sibling tools…
Attacks that exploit this kind of access
The rule that runs toolx safely
PolicyLayer is an MCP gateway: it sits between your AI agents and PromptX, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For toolx, this is the rule to start with:
toolx stays usable, but rate-capped: a runaway agent can't fire it dozens of times a minute. Everything else on the server is denied unless you say otherwise.
The button opens the PolicyLayer dashboard: create your workspace, connect PromptX, apply this rule, and every toolx call is checked against it from then on.
Questions about toolx
ToolX runtime — load and execute PromptX ecosystem tools What It Does Universal interface for calling PromptX tools (file ops, PDF reading, role creation, etc.). Input is a YAML document specifying the tool, mode, and parameters. Modes | Mode | Purpose | |---|---| | manual | Read tool documentation (always do this first) | | execute | Run the tool with parameters | | configure | Set environment variables for a tool | | log | View tool execution logs | | dryrun | Preview without executing | Examples Read tool manual (do this first): \. It is categorised as a Execute tool in the PromptX MCP Server, which means it can trigger actions or run processes. Use rate limits and argument validation.
Register the PromptX MCP server in PolicyLayer and add a rule for toolx: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches PromptX. Nothing to install.
toolx is a Execute tool with high risk. Execute tools should be rate-limited and have argument validation enabled.
Yes. Add a rate_limit block to the toolx rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for toolx. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
toolx is provided by the PromptX MCP server (deepractice/promptx). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on PromptX, and thousands of servers like it.
Across the catalogue