# pr-update

Updates pull request metadata (title, body, labels, assignees, reviewers, milestone, base branch, projects). Returns structured data with PR number and URL.

Agent View of the PolicyLayer registry record for `pr-update`. HTML page: https://policylayer.com/tools/io-github-dave-london-lint/pr-update

## Facts

- Tool: `pr-update`
- Server: Lint (`Dave-London/Pare`) — https://policylayer.com/tools/io-github-dave-london-lint.md
- Homepage: https://github.com/Dave-London/pare
- Risk category: Write (Medium risk)
- Registry record: grade F, identity unverified
- Server rate-limited: no
- Parameters: 0
- Recommended policy verdict: Rate-limited

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "pr-update",
    "arguments": {}
  }
}
```

## Why pr-update is rated Medium

The tool modifies PR state (title, body, labels, assignees, etc.) but does not delete data or trigger financial transactions. Updates are reversible through subsequent API calls. The severity is medium because an agent could misuse this to modify PR properties in ways that mislead reviewers or disrupt workflow, but changes are not destructive and can be corrected.

From the tool's own definition: "Tool explicitly performs update operations on pull request metadata: 'Updates pull request metadata (title, body, labels, assignees, reviewers, milestone, base branch, projects).' These are reversible modifications to PR attributes."

## Use case

AI agents use pr-update to create or update resources in Lint, usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your Lint environment.

## Recommended policy (PolicyLayer)

Verdict: **Rate-limited**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Lint:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "pr-update": {
      "limits": [
        {
          "counter": "pr-update_rate",
          "window": "minute",
          "max": 30,
          "scope": "grant"
        }
      ]
    }
  }
}
```

## Other tools on Lint (201)

- `branch` — Destructive — https://policylayer.com/tools/io-github-dave-london-lint/branch.md
- `clean` — Destructive — https://policylayer.com/tools/io-github-dave-london-lint/clean.md
- `package-clean` — Destructive — https://policylayer.com/tools/io-github-dave-london-lint/package-clean.md
- `pr-close` — Destructive — https://policylayer.com/tools/io-github-dave-london-lint/pr-close.md
- `remove` — Destructive — https://policylayer.com/tools/io-github-dave-london-lint/remove.md
- `reset` — Destructive — https://policylayer.com/tools/io-github-dave-london-lint/reset.md
- `secret-delete` — Destructive — https://policylayer.com/tools/io-github-dave-london-lint/secret-delete.md
- `tag` — Destructive — https://policylayer.com/tools/io-github-dave-london-lint/tag.md
- `variable-delete` — Destructive — https://policylayer.com/tools/io-github-dave-london-lint/variable-delete.md
- `workspace` — Destructive — https://policylayer.com/tools/io-github-dave-london-lint/workspace.md
- `worktree` — Destructive — https://policylayer.com/tools/io-github-dave-london-lint/worktree.md
- `add` — Execute — https://policylayer.com/tools/io-github-dave-london-lint/add.md
- `add-package` — Execute — https://policylayer.com/tools/io-github-dave-london-lint/add-package.md
- `ansible-galaxy` — Execute — https://policylayer.com/tools/io-github-dave-london-lint/ansible-galaxy.md
- `ansible-playbook` — Execute — https://policylayer.com/tools/io-github-dave-london-lint/ansible-playbook.md
- `api` — Execute — https://policylayer.com/tools/io-github-dave-london-lint/api.md
- `apply` — Execute — https://policylayer.com/tools/io-github-dave-london-lint/apply.md
- `bazel` — Execute — https://policylayer.com/tools/io-github-dave-london-lint/bazel.md
- `biome-check` — Execute — https://policylayer.com/tools/io-github-dave-london-lint/biome-check.md
- `bisect` — Execute — https://policylayer.com/tools/io-github-dave-london-lint/bisect.md
- `black` — Execute — https://policylayer.com/tools/io-github-dave-london-lint/black.md
- `build` — Execute — https://policylayer.com/tools/io-github-dave-london-lint/build.md
- `bundle-exec` — Execute — https://policylayer.com/tools/io-github-dave-london-lint/bundle-exec.md
- `bundle-install` — Execute — https://policylayer.com/tools/io-github-dave-london-lint/bundle-install.md
- `check` — Execute — https://policylayer.com/tools/io-github-dave-london-lint/check.md
- `cherry-pick` — Execute — https://policylayer.com/tools/io-github-dave-london-lint/cherry-pick.md
- `clippy` — Execute — https://policylayer.com/tools/io-github-dave-london-lint/clippy.md
- `cmake` — Execute — https://policylayer.com/tools/io-github-dave-london-lint/cmake.md
- `compose-build` — Execute — https://policylayer.com/tools/io-github-dave-london-lint/compose-build.md
- `compose-down` — Execute — https://policylayer.com/tools/io-github-dave-london-lint/compose-down.md
- …and 171 more: https://policylayer.com/tools/io-github-dave-london-lint.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=io-github-dave-london-lint · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/io-github-dave-london-lint
