# dephq_app_check

Run the platform runtime readiness checks for an owned app.

Agent View of the PolicyLayer registry record for `dephq_app_check`. HTML page: https://policylayer.com/tools/dephq-mcp/dephq-app-check

## Facts

- Tool: `dephq_app_check`
- Server: Dephq (`@dephq/mcp`) — https://policylayer.com/tools/dephq-mcp.md
- Install: `npx -y @dephq/mcp`
- Homepage: https://www.npmjs.com/package/@dephq/mcp
- Risk category: Execute (High risk)
- Registry record: grade F, identity unverified
- Server rate-limited: no
- Parameters: 1 (1 required)
- Recommended policy verdict: Rate-limited

## Parameters

| Parameter | Type | Required | Description |
| --- | --- | --- | --- |
| `app_id` | string | yes |  |

Parameters from the server's own tool schema.

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "dephq_app_check",
    "arguments": {
      "app_id": "<app_id>"
    }
  }
}
```

## Why dephq_app_check is rated High

The tool runs checks on a live app, which constitutes executing an operation against external infrastructure. While it appears to be read-only in intent (readiness checks), 'run' implies active execution of operations rather than passive data retrieval. Misuse risk is medium since it could trigger side effects on the platform or reveal sensitive configuration details.

From the tool's own definition: "'Run the platform runtime readiness checks' — actively executes checks against an app"

## Use case

AI agents invoke dephq_app_check to trigger actions in Dephq. What it does depends on the arguments the agent supplies, and its effects often reach beyond the immediate call: builds kicked off, notifications sent, workflows started.

## Recommended policy (PolicyLayer)

Verdict: **Rate-limited**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Dephq:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "dephq_app_check": {
      "limits": [
        {
          "counter": "dephq_app_check_rate",
          "window": "minute",
          "max": 10,
          "scope": "grant"
        }
      ]
    }
  }
}
```

## Other tools on Dephq (11)

- `dephq_app_unpublish` — Destructive — https://policylayer.com/tools/dephq-mcp/dephq-app-unpublish.md
- `dephq_account` — Read — https://policylayer.com/tools/dephq-mcp/dephq-account.md
- `dephq_app_show` — Read — https://policylayer.com/tools/dephq-mcp/dephq-app-show.md
- `dephq_app_versions` — Read — https://policylayer.com/tools/dephq-mcp/dephq-app-versions.md
- `dephq_apps_list` — Read — https://policylayer.com/tools/dephq-mcp/dephq-apps-list.md
- `dephq_project_validate` — Read — https://policylayer.com/tools/dephq-mcp/dephq-project-validate.md
- `dephq_sync_status` — Read — https://policylayer.com/tools/dephq-mcp/dephq-sync-status.md
- `dephq_app_publish` — Write — https://policylayer.com/tools/dephq-mcp/dephq-app-publish.md
- `dephq_app_rollback` — Write — https://policylayer.com/tools/dephq-mcp/dephq-app-rollback.md
- `dephq_project_init` — Write — https://policylayer.com/tools/dephq-mcp/dephq-project-init.md
- `dephq_project_sync` — Write — https://policylayer.com/tools/dephq-mcp/dephq-project-sync.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=dephq-mcp · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/dephq-mcp
