commonsensepass_check
Run the verdict-only CommonSensePass sanity gate before a worker claims healthy, quiet, no_work, pass, done, merge_ready, duplicate_wake, or route.
This record as markdown: /tools/io-github-malamutemayhem-unclick-mcp-server/commonsensepass-check.md
What commonsensepass_check does on UnClick
AI agents invoke commonsensepass_check to trigger actions in UnClick. What it does depends on the arguments the agent supplies, and its effects often reach beyond the immediate call: builds kicked off, notifications sent, workflows started.
| Parameter | Type | Required | Description |
|---|---|---|---|
claim | string | Yes | Worker claim to sanity-check. |
context | object | Yes | Evidence packet for the claim, such as todos, active_jobs, PR state, wake state, SHAs, or lane evidence. |
evidence | array | — | Optional evidence entries to echo when no rule-specific evidence is available. |
Parameters from the server's own tool schema.
Why commonsensepass_check is rated High
The tool runs a sanity check gate that controls downstream worker state transitions. While it appears to be a read/validation operation, 'Run the ... sanity gate' implies execution of a process that has real effects on workflow routing and worker claims. It is not purely passive data retrieval, as its verdict directly gates operational state changes.
From the tool's definition 'Run the verdict-only CommonSensePass sanity gate' — the tool actively executes a gating/validation process that determines whether a worker can claim certain states (healthy, quiet, no_work, pass, done, merge_ready, duplicate_wake, or route).
Attacks that exploit this kind of access
The rule that runs commonsensepass_check safely
PolicyLayer is an MCP gateway: it sits between your AI agents and UnClick, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For commonsensepass_check, this is the rule to start with:
commonsensepass_check stays usable, but rate-capped: a runaway agent can't fire it dozens of times a minute. Everything else on the server is denied unless you say otherwise.
The button opens the PolicyLayer dashboard: create your workspace, connect UnClick, apply this rule, and every commonsensepass_check call is checked against it from then on.
Questions about commonsensepass_check
Run the verdict-only CommonSensePass sanity gate before a worker claims healthy, quiet, no_work, pass, done, merge_ready, duplicate_wake, or route. It is categorised as a Execute tool in the UnClick MCP Server, which means it can trigger actions or run processes. Use rate limits and argument validation.
commonsensepass_check accepts 3 parameters: claim, context, evidence. Required: claim, context. The full parameter table on this page comes from the server's own tool schema.
Register the UnClick MCP server in PolicyLayer and add a rule for commonsensepass_check: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches UnClick. Nothing to install.
commonsensepass_check is a Execute tool with high risk. Execute tools should be rate-limited and have argument validation enabled.
Yes. Add a rate_limit block to the commonsensepass_check rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for commonsensepass_check. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
commonsensepass_check is provided by the UnClick MCP server (@unclick/mcp-server). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on UnClick, and thousands of servers like it.
Across the catalogue