apro-socialmedia-proxy
APRO v2 socialmedia/proxy (POST JSON): forwards one read to the platform API. Call apro-socialmedia-support-paths first. method must be exactly Get. path must be a supported route (e.g. /2/...). Docs: https://docs.apro.com/ai-oracle/getting-started/quickstart/apro-ai-oracle-api-v2/social-media
This record as markdown: /tools/demomagic-lucy-apro/apro-socialmedia-proxy.md
What apro-socialmedia-proxy does on Lucy Apro
AI agents call apro-socialmedia-proxy to retrieve information from Lucy Apro without modifying anything. It is typically the context-gathering step in research, monitoring, and reporting workflows, before the agent takes action elsewhere.
| Parameter | Type | Required | Description |
|---|---|---|---|
name | string | — | Same platform name as support_paths, typically Twitter for X. Must match what you used in apro-socialmedia-support-paths. |
path | string | — | Path and query for the platform API. Match keys from apro-socialmedia-support-paths (e.g. /2/users/by?usernames=elonmusk or /2/tweets?ids=...). Docs also show p |
method | string | — | APRO expects the literal string Get (Pascal case), per official examples — not GET, not POST, not get. |
Parameters from the server's own tool schema.
Why apro-socialmedia-proxy is rated Low
The tool is primarily a Read operation—it forwards GET requests to social media platforms and retrieves data. It does not create, modify, or delete data. Severity is medium rather than low because proxying to external APIs introduces potential for information disclosure, rate-limiting issues, or exposure of sensitive social media data depending on what paths are accessible.
From the tool's definition 'forwards one read to the platform API' and 'method must be exactly Get' indicate this tool retrieves data without modification. However, it proxies requests to external social media platform APIs.
Risk signalsAccepts file system path (path)
Attacks that exploit this kind of access
The rule that runs apro-socialmedia-proxy safely
PolicyLayer is an MCP gateway: it sits between your AI agents and Lucy Apro, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For apro-socialmedia-proxy, this is the rule to start with:
apro-socialmedia-proxy is read-only, so it stays allowed. Everything else on the server is denied unless you say otherwise.
The button opens the PolicyLayer dashboard: create your workspace, connect Lucy Apro, apply this rule, and every apro-socialmedia-proxy call is checked against it from then on.
Questions about apro-socialmedia-proxy
APRO v2 socialmedia/proxy (POST JSON): forwards one read to the platform API. Call apro-socialmedia-support-paths first. method must be exactly Get. path must be a supported route (e.g. /2/...). Docs: https://docs.apro.com/ai-oracle/getting-started/quickstart/apro-ai-oracle-api-v2/social-media. It is categorised as a Read tool in the Lucy Apro MCP Server, which means it retrieves data without modifying state.
apro-socialmedia-proxy accepts 3 parameters: name, path, method. The full parameter table on this page comes from the server's own tool schema.
Register the Lucy Apro MCP server in PolicyLayer and add a rule for apro-socialmedia-proxy: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches Lucy Apro. Nothing to install.
apro-socialmedia-proxy is a Read tool with low risk. Read-only tools are generally safe to allow by default.
Yes. Add a rate_limit block to the apro-socialmedia-proxy rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for apro-socialmedia-proxy. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
apro-socialmedia-proxy is provided by the Lucy Apro MCP server (demomagic/lucy-apro). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on Lucy Apro, and thousands of servers like it.
This server
Across the catalogue