list_devices
List devices — YOUR OWN by default (owner-scoped to the calling account: the same reach the dashboard gives you), or the WHOLE fleet with all:true (devices:view operators only; re-verified server-side — for a non-operator all is rejected, never silently widened). Each row is a slim projection: uu...
This record as markdown: /tools/dev-busymate-busymate-devtools/list-devices.md
What list_devices does on Busymate DevTools
AI agents call list_devices to retrieve information from Busymate DevTools without modifying anything. It is typically the context-gathering step in research, monitoring, and reporting workflows, before the agent takes action elsewhere.
| Parameter | Type | Required | Description |
|---|---|---|---|
all | boolean | — | devices:view operators only — list EVERY device (the whole fleet) instead of just YOUR OWN. |
limit | number | — | Max devices (default 200, cap 500). |
Parameters from the server's own tool schema.
Why list_devices is rated Low
This tool retrieves and queries device information without modifying, deleting, or executing operations. It is a read-only operation. Severity is medium rather than low because: (1) listing all devices in a fleet (`all:true`) requires operator privileges but could expose sensitive device inventory and network topology if access controls fail, and (2) returned metadata (vpn_state, connection_type, pac configuration)…
From the tool's definition Tool name is 'list_devices' and description states 'List devices' with scope control: 'YOUR OWN by default (owner-scoped to the calling account)' or 'WHOLE fleet with `all:true` (devices:view operators only)'.
Attacks that exploit this kind of access
The rule that runs list_devices safely
PolicyLayer is an MCP gateway: it sits between your AI agents and Busymate DevTools, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For list_devices, this is the rule to start with:
list_devices is read-only, so it stays allowed. Everything else on the server is denied unless you say otherwise.
The button opens the PolicyLayer dashboard: create your workspace, connect Busymate DevTools, apply this rule, and every list_devices call is checked against it from then on.
Questions about list_devices
List devices — YOUR OWN by default (owner-scoped to the calling account: the same reach the dashboard gives you), or the WHOLE fleet with all:true (devices:view operators only; re-verified server-side — for a non-operator all is rejected, never silently widened). Each row is a slim projection: uuid, name, model, platform, os_version, parent_device_id + parent_name (farm/iOS children resolve their host's NAME), online + vpn_state (live device_status), last_seen_at, the per-device connection_type override (null = inherits user → global), and pac_port/pac_url for PAC-provisioned devices. Fleet rows also resolve each owner to a human name. Use to answer "what devices do I own" / "list my devices" / "which devices are online"; feed the returned uuid into get_device / rename_device / … Read-only, no confirm. Returns { ok, scope: own|fleet, count, devices:[…] }. It is categorised as a Read tool in the Busymate DevTools MCP Server, which means it retrieves data without modifying state.
list_devices accepts 2 parameters: all, limit. The full parameter table on this page comes from the server's own tool schema.
Register the Busymate DevTools MCP server in PolicyLayer and add a rule for list_devices: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches Busymate DevTools. Nothing to install.
list_devices is a Read tool with low risk. Read-only tools are generally safe to allow by default.
Yes. Add a rate_limit block to the list_devices rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for list_devices. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
list_devices is provided by the Busymate DevTools MCP server (https://mcp.busymate.dev). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on Busymate DevTools, and thousands of servers like it.
This server
Across the catalogue