register_docx_derivative
[MAINTENANCE] W1-K — record that derivative_path (e.g. a rendered PDF/DOCX export) was generated FROM source_path at a known content state. source_content_hash is the CALLER-computed content hash of the source document at generation time (the server never reads either file itself — hash it locall...
This record as markdown: /tools/io-github-ajc3xc-meridian/register-docx-derivative.md
What register_docx_derivative does on Meridian
AI agents use register_docx_derivative to create or update resources in Meridian, usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your Meridian environment.
| Parameter | Type | Required | Description |
|---|---|---|---|
notes | string | — | Optional free-text note about this derivative. |
project_id | string | — | |
session_id | string | Yes | |
source_path | string | Yes | Path to the canonical .docx source document. Need not be project-relative — a docx source routinely lives outside the repo. |
generated_at | string | — | ISO-8601 timestamp the derivative was generated. Defaults to now (UTC) when omitted. |
project_name | string | — | Project name — an alternative to project_id; resolved to the id internally. project_id wins if both are given. |
derivative_path | string | Yes | Path to the derivative .docx document generated from source_path. |
generating_tool | string | — | Name/version of the tool or script that generated this derivative. |
source_content_hash | string | Yes | Caller-computed content hash of source_path's CURRENT bytes at generation time. Required — this is the provenance anchor verify_docx_diff later compares against |
derivative_content_hash | string | — | Optional caller-computed content hash of derivative_path's bytes at generation time. |
Parameters from the server's own tool schema.
Why register_docx_derivative is rated Medium
An AI agent can call register_docx_derivative faster than any human can review: one bad instruction and it creates or modifies resources in Meridian by the hundred, each call as confident as the last.
Risk signalsAccepts file system path (source_path) · High parameter count (10 properties)
Attacks that exploit this kind of access
The rule that runs register_docx_derivative safely
PolicyLayer is an MCP gateway: it sits between your AI agents and Meridian, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For register_docx_derivative, this is the rule to start with:
register_docx_derivative stays usable, but capped: an agent stuck in a loop can't make hundreds of changes a minute. Everything else on the server is denied unless you say otherwise.
The button opens the PolicyLayer dashboard: create your workspace, connect Meridian, apply this rule, and every register_docx_derivative call is checked against it from then on.
Questions about register_docx_derivative
[MAINTENANCE] W1-K — record that derivative_path (e.g. a rendered PDF/DOCX export) was generated FROM source_path at a known content state. source_content_hash is the CALLER-computed content hash of the source document at generation time (the server never reads either file itself — hash it locally, e.g. sha256, before calling this). Always creates a NEW row with status='candidate' — re-rendering the same source/derivative pair over time is expected and never overwrites a prior registration; use promote_docx_candidate to make one candidate the accepted derivative for its source. generating_tool names the tool/script that produced it (e.g. 'pandoc 3.1' or 'export_pdf.py'); generated_at defaults to now (UTC) when omitted. Returns {derivative: {...}} including the new derivative_id. Persistent-state disclosure: on hosted Meridian, supplied text and project/session metadata -- including task log entries, pinned decisions, sprint items, notes, handoff/goal state, and HITL queue items -- are sent to and stored in Meridian's service, in an isolated per-tenant Postgres database (Neon); self-hosted deployments keep the same categories in the configured local SQLite/Postgres database. This data is visible in the dashboard and API, and may resurface in later project context or handoffs. Notes and pinned decisions can be deleted individually; task log entries and sprint items can be deleted via the dashboard/API (not exposed as an agent-facing tool); HITL queue items and handoff state have no per-record delete. Full removal of any of this data is available via project or account deletion, using the documented controls. Do not include secrets. It is categorised as a Write tool in the Meridian MCP Server, which means it can create or modify data. Consider rate limits to prevent runaway writes.
register_docx_derivative accepts 10 parameters: notes, project_id, session_id, source_path, generated_at, project_name, derivative_path, generating_tool, source_content_hash, derivative_content_hash. Required: session_id, source_path, derivative_path, source_content_hash. The full parameter table on this page comes from the server's own tool schema.
Register the Meridian MCP server in PolicyLayer and add a rule for register_docx_derivative: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches Meridian. Nothing to install.
register_docx_derivative is a Write tool with medium risk. Write tools should be rate-limited to prevent accidental bulk modifications.
Yes. Add a rate_limit block to the register_docx_derivative rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for register_docx_derivative. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
register_docx_derivative is provided by the Meridian MCP server (@meridianmcp/mcp). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on Meridian, and thousands of servers like it.
This server
Across the catalogue