# sources

List all data sources with license, attribution and availability. Takes no arguments. Shows which upstream sources InfraNode bundles and whether each is currently active. Read-only.

Agent View of the PolicyLayer registry record for `sources`. HTML page: https://policylayer.com/tools/dev-infranode-infranode/sources

## Facts

- Tool: `sources`
- Server: InfraNode (`https://mcp.infranode.dev/mcp`) — https://policylayer.com/tools/dev-infranode-infranode.md
- Homepage: https://github.com/street1983nk/infranode
- Risk category: Read (Low risk)
- Registry record: grade C, identity unverified
- Server auth posture: open
- Server rate-limited: no
- Parameters: 0
- Recommended policy verdict: Allowed

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "sources",
    "arguments": {}
  }
}
```

## Why sources is rated Low

This tool retrieves and queries metadata about data sources—a classic read operation with zero side effects. No data is modified, deleted, executed, or financially committed. The read-only designation and passive information retrieval nature confirm the lowest-severity category.

From the tool's own definition: "Tool description explicitly states 'Read-only' and the function 'List all data sources' indicates data retrieval with no side effects. Takes no arguments and only shows metadata about upstream sources, licenses, and availability status."

Risk signals: Bulk/mass operation — affects multiple targets

## Use case

AI agents call sources to retrieve information from InfraNode without modifying anything. It is typically the context-gathering step in research, monitoring, and reporting workflows, before the agent takes action elsewhere.

## Recommended policy (PolicyLayer)

Verdict: **Allowed**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches InfraNode:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "sources": {}
  }
}
```

## Other tools on InfraNode (11)

- `air_quality` — Read — https://policylayer.com/tools/dev-infranode-infranode/air-quality.md
- `compare` — Read — https://policylayer.com/tools/dev-infranode-infranode/compare.md
- `get_city` — Read — https://policylayer.com/tools/dev-infranode-infranode/get-city.md
- `get_city_overview` — Read — https://policylayer.com/tools/dev-infranode-infranode/get-city-overview.md
- `get_city_resource` — Read — https://policylayer.com/tools/dev-infranode-infranode/get-city-resource.md
- `list_cities` — Read — https://policylayer.com/tools/dev-infranode-infranode/list-cities.md
- `pois` — Read — https://policylayer.com/tools/dev-infranode-infranode/pois.md
- `station_board_arrivals` — Read — https://policylayer.com/tools/dev-infranode-infranode/station-board-arrivals.md
- `station_board_departures` — Read — https://policylayer.com/tools/dev-infranode-infranode/station-board-departures.md
- `transit_departures` — Read — https://policylayer.com/tools/dev-infranode-infranode/transit-departures.md
- `weather` — Read — https://policylayer.com/tools/dev-infranode-infranode/weather.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=dev-infranode-infranode · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/dev-infranode-infranode
