add_search_console_site
Add a property to the connected Google account. TWO THINGS THAT MUST REACH THE USER, and the answer states both: (1) ADDING IS NOT VERIFYING — the property arrives with the account as an unverified user and EVERY read on it is refused until ownership is proven with a DNS record, an HTML file or a...
This record as markdown: /tools/hermoso/add-search-console-site.md
What add_search_console_site does on Hermoso
AI agents use add_search_console_site to create or update resources in Hermoso, usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your Hermoso environment.
Why add_search_console_site is rated Medium
An AI agent can call add_search_console_site faster than any human can review: one bad instruction and it creates or modifies resources in Hermoso by the hundred, each call as confident as the last.
Risk signalsBulk/mass operation — affects multiple targets
Attacks that exploit this kind of access
The rule that runs add_search_console_site safely
PolicyLayer is an MCP gateway: it sits between your AI agents and Hermoso, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For add_search_console_site, this is the rule to start with:
add_search_console_site stays usable, but capped: an agent stuck in a loop can't make hundreds of changes a minute. Everything else on the server is denied unless you say otherwise.
The button opens the PolicyLayer dashboard: create your workspace, connect Hermoso, apply this rule, and every add_search_console_site call is checked against it from then on.
Questions about add_search_console_site
Add a property to the connected Google account. TWO THINGS THAT MUST REACH THE USER, and the answer states both: (1) ADDING IS NOT VERIFYING — the property arrives with the account as an unverified user and EVERY read on it is refused until ownership is proven with a DNS record, an HTML file or a tag, which no API can do and which the user completes in Search Console itself; (2) the new property is NOT yet shared with this profile, so someone has to tick it under Settings > Connectors > Google Search Console > Manage accounts (or call list_connector_accounts with provider google_search_console, then set_connector_accounts) before any tool here can use it. The permission level is READ BACK from Google, so the answer says which of those two states it is actually in. 0 credits. It is categorised as a Write tool in the Hermoso MCP Server, which means it can create or modify data. Consider rate limits to prevent runaway writes.
Register the Hermoso MCP server in PolicyLayer and add a rule for add_search_console_site: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches Hermoso. Nothing to install.
add_search_console_site is a Write tool with medium risk. Write tools should be rate-limited to prevent accidental bulk modifications.
Yes. Add a rate_limit block to the add_search_console_site rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for add_search_console_site. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
add_search_console_site is provided by the Hermoso MCP server (https://app.hermoso.ai/mcp). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on Hermoso, and thousands of servers like it.
This server
Across the catalogue