calendly_list_invitees
List invitees for a Calendly event
This record as markdown: /tools/io-github-alifanov-scopegate/calendly-list-invitees.md
What calendly_list_invitees does on ScopeGate
AI agents call calendly_list_invitees to retrieve information from ScopeGate without modifying anything. It is typically the context-gathering step in research, monitoring, and reporting workflows, before the agent takes action elsewhere.
Why calendly_list_invitees is rated Low
This tool retrieves and lists existing calendar event invitee information without creating, modifying, deleting, or executing any operations. It has no side effects beyond data retrieval. The blast radius of misuse is minimal—an agent gaining access can view attendee lists but cannot modify calendars, send invitations, or perform irreversible actions. Classified as Read with low severity.
From the tool's definition Tool name includes 'list' (retrieves data); description states 'List invitees' with no modification, deletion, or execution capability mentioned. The action is purely informational—querying event attendee data.
Attacks that exploit this kind of access
The rule that runs calendly_list_invitees safely
PolicyLayer is an MCP gateway: it sits between your AI agents and ScopeGate, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For calendly_list_invitees, this is the rule to start with:
calendly_list_invitees is read-only, so it stays allowed. Everything else on the server is denied unless you say otherwise.
The button opens the PolicyLayer dashboard: create your workspace, connect ScopeGate, apply this rule, and every calendly_list_invitees call is checked against it from then on.
Questions about calendly_list_invitees
List invitees for a Calendly event. It is categorised as a Read tool in the ScopeGate MCP Server, which means it retrieves data without modifying state.
Register the ScopeGate MCP server in PolicyLayer and add a rule for calendly_list_invitees: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches ScopeGate. Nothing to install.
calendly_list_invitees is a Read tool with low risk. Read-only tools are generally safe to allow by default.
Yes. Add a rate_limit block to the calendly_list_invitees rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for calendly_list_invitees. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
calendly_list_invitees is provided by the ScopeGate MCP server (https://mcp.scopegate.cloud/{api_key}). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on ScopeGate, and thousands of servers like it.
This server
Across the catalogue