upload_drone_script
Upload a DroneLang script to an autonomous drone (DroneLang is a simple scripting language. Scripts run once per tick. The drone executes the first matching IF branch as one game action. Each drone_control skill level allows one additional drone to run scripts concurrently. Pass empty script to c...
This record as markdown: /tools/io-github-statico-alt-spacemolt/upload-drone-script.md
What upload_drone_script does on SpaceMolt
AI agents invoke upload_drone_script to trigger actions in SpaceMolt. What it does depends on the arguments the agent supplies, and its effects often reach beyond the immediate call: builds kicked off, notifications sent, workflows started.
| Parameter | Type | Required | Description |
|---|---|---|---|
script | string | Yes | DroneLang script source (max 2000 chars). Pass empty string to clear. |
drone_id | string | Yes | ID of the drone to program |
session_id | string | Yes | Your session ID from login/register |
Parameters from the server's own tool schema.
Why upload_drone_script is rated High
This tool uploads and runs code on an autonomous agent (drone) that executes game actions each tick. It triggers ongoing, automated execution of arbitrary script logic, which can have wide-ranging in-game effects (mining, trading, attacking, etc.) per tick.
From the tool's definition 'Upload a DroneLang script to an autonomous drone' and 'The drone executes the first matching IF branch as one game action'
Risk signalsAccepts freeform code/query input (script)
Attacks that exploit this kind of access
The rule that runs upload_drone_script safely
PolicyLayer is an MCP gateway: it sits between your AI agents and SpaceMolt, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For upload_drone_script, this is the rule to start with:
upload_drone_script stays usable, but rate-capped: a runaway agent can't fire it dozens of times a minute. Everything else on the server is denied unless you say otherwise.
The button opens the PolicyLayer dashboard: create your workspace, connect SpaceMolt, apply this rule, and every upload_drone_script call is checked against it from then on.
Questions about upload_drone_script
Upload a DroneLang script to an autonomous drone (DroneLang is a simple scripting language. Scripts run once per tick. The drone executes the first matching IF branch as one game action. Each drone_control skill level allows one additional drone to run scripts concurrently. Pass empty script to clear.). It is categorised as a Execute tool in the SpaceMolt MCP Server, which means it can trigger actions or run processes. Use rate limits and argument validation.
upload_drone_script accepts 3 parameters: script, drone_id, session_id. Required: script, drone_id, session_id. The full parameter table on this page comes from the server's own tool schema.
Register the SpaceMolt MCP server in PolicyLayer and add a rule for upload_drone_script: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches SpaceMolt. Nothing to install.
upload_drone_script is a Execute tool with high risk. Execute tools should be rate-limited and have argument validation enabled.
Yes. Add a rate_limit block to the upload_drone_script rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for upload_drone_script. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
upload_drone_script is provided by the SpaceMolt MCP server (https://game.spacemolt.com/mcp). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on SpaceMolt, and thousands of servers like it.
Across the catalogue