link_tiktok_tto_video
Ask a creator to link one of their public videos to a TikTok One campaign, or withdraw that request. THIS PUTS A NOTIFICATION IN A REAL PERSON’S TIKTOK INBOX, AND REPEATING IT IS A REMINDER RATHER THAN A RETRY: TikTok refuses a second LINK within 24 hours of the last, allows at most two reminders...
This record as markdown: /tools/hermoso/link-tiktok-tto-video.md
What link_tiktok_tto_video does on Hermoso
AI agents call link_tiktok_tto_video to permanently remove resources in Hermoso, typically in cleanup and lifecycle workflows. It does its job in a single call, and there is no undo.
Why link_tiktok_tto_video is rated Critical
An AI agent that decides to call link_tiktok_tto_video doesn't hesitate, doesn't double-check, and doesn't stop at one. Whatever it removes from Hermoso is gone. There is no undo for destructive operations.
Attacks that exploit this kind of access
The rule that runs link_tiktok_tto_video safely
PolicyLayer is an MCP gateway: it sits between your AI agents and Hermoso, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For link_tiktok_tto_video, this is the rule to start with:
link_tiktok_tto_video is removed from the agent's tool list entirely, so the agent never calls it. The rest of the server keeps working.
The button opens the PolicyLayer dashboard: create your workspace, connect Hermoso, apply this rule, and every link_tiktok_tto_video call is checked against it from then on.
Questions about link_tiktok_tto_video
Ask a creator to link one of their public videos to a TikTok One campaign, or withdraw that request. THIS PUTS A NOTIFICATION IN A REAL PERSON’S TIKTOK INBOX, AND REPEATING IT IS A REMINDER RATHER THAN A RETRY: TikTok refuses a second LINK within 24 hours of the last, allows at most two reminders in total, and counts them; so never re-send after a transient failure without reading list_tiktok_tto_link_requests first. REVOKE has its own one-way rule: it works only while the creator has neither accepted nor rejected, TikTok allows it once per request, and there is no un-revoke. TikTok also refuses a video already linked to any other campaign, and refuses one whose creator was never invited. Free. It is categorised as a Destructive tool in the Hermoso MCP Server, which means it can permanently delete or destroy data. Block by default and require explicit approval.
Register the Hermoso MCP server in PolicyLayer and add a rule for link_tiktok_tto_video: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches Hermoso. Nothing to install.
link_tiktok_tto_video is a Destructive tool with critical risk. Critical-risk tools should be blocked by default and only enabled with explicit human approval.
Yes. Add a rate_limit block to the link_tiktok_tto_video rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for link_tiktok_tto_video. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
link_tiktok_tto_video is provided by the Hermoso MCP server (https://app.hermoso.ai/mcp). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on Hermoso, and thousands of servers like it.
Across the catalogue