# workflow_conditional_step

Evaluate a condition against the stepResults argument and execute one of two tool branches. Supports built-in predicates: always_true, always_false, any_step_failed, success_rate_gte_N (N=0-100), variable_equals_KEY_VALUE, variable_contains_KEY_VALUE, variable_matches_KEY_REGEX, plus history-driven predicates history_failure_rate_gte_N / history_failure_rate_lte_N, last_run_failed[:workflowId], recent_steps_failing_L[:workflowId], history_fallback_rate_gte_N / history_fallback_rate_lte_N. History predicates read the workflow run store (the last 10 runs of the workflow named by the :workflowId suffix, or the current workflow when none is given); they evaluate false when no history exists. When stepResults is omitted, an empty set is used, so value-based predicates (variable_*, success_rate_gte_N, any_step_failed) will not match.

Agent View of the PolicyLayer registry record for `workflow_conditional_step`. HTML page: https://policylayer.com/tools/io-github-vmoranv-jshookmcp/workflow-conditional-step

## Facts

- Tool: `workflow_conditional_step`
- Server: Jshookmcp (`@jshookmcp/jshook`) — https://policylayer.com/tools/io-github-vmoranv-jshookmcp.md
- Install: `npx -y @jshookmcp/jshook`
- Homepage: https://github.com/vmoranv/jshookmcp
- Risk category: Execute (High risk)
- Registry record: grade F, identity unverified
- Server rate-limited: no
- Parameters: 0
- Recommended policy verdict: Rate-limited

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "workflow_conditional_step",
    "arguments": {}
  }
}
```

## Why workflow_conditional_step is rated High

Conditionally executes arbitrary tool branches based on evaluated predicates, allowing workflow logic control with potential side effects.

From the tool's own definition: "Evaluate condition, execute tool branches, supports predicates"

## Use case

AI agents invoke workflow_conditional_step to trigger actions in Jshookmcp. What it does depends on the arguments the agent supplies, and its effects often reach beyond the immediate call: builds kicked off, notifications sent, workflows started.

## Recommended policy (PolicyLayer)

Verdict: **Rate-limited**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Jshookmcp:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "workflow_conditional_step": {
      "limits": [
        {
          "counter": "workflow_conditional_step_rate",
          "window": "minute",
          "max": 10,
          "scope": "grant"
        }
      ]
    }
  }
}
```

## Other tools on Jshookmcp (735)

- `adb_uninstall` — Destructive — https://policylayer.com/tools/io-github-vmoranv-jshookmcp/adb-uninstall.md
- `cleanup_artifacts` — Destructive — https://policylayer.com/tools/io-github-vmoranv-jshookmcp/cleanup-artifacts.md
- `clear_all_caches` — Destructive — https://policylayer.com/tools/io-github-vmoranv-jshookmcp/clear-all-caches.md
- `clear_collected_data` — Destructive — https://policylayer.com/tools/io-github-vmoranv-jshookmcp/clear-collected-data.md
- `dart_destroy_session` — Destructive — https://policylayer.com/tools/io-github-vmoranv-jshookmcp/dart-destroy-session.md
- `exploit_cache_clear` — Destructive — https://policylayer.com/tools/io-github-vmoranv-jshookmcp/exploit-cache-clear.md
- `exploit_cache_invalidate` — Destructive — https://policylayer.com/tools/io-github-vmoranv-jshookmcp/exploit-cache-invalidate.md
- `extension_uninstall` — Destructive — https://policylayer.com/tools/io-github-vmoranv-jshookmcp/extension-uninstall.md
- `ghidra_decompile` — Destructive — https://policylayer.com/tools/io-github-vmoranv-jshookmcp/ghidra-decompile.md
- `ida_decompile` — Destructive — https://policylayer.com/tools/io-github-vmoranv-jshookmcp/ida-decompile.md
- `jadx_decompile_apk` — Destructive — https://policylayer.com/tools/io-github-vmoranv-jshookmcp/jadx-decompile-apk.md
- `manual_token_cleanup` — Destructive — https://policylayer.com/tools/io-github-vmoranv-jshookmcp/manual-token-cleanup.md
- `memory_antidetection` — Destructive — https://policylayer.com/tools/io-github-vmoranv-jshookmcp/memory-antidetection.md
- `memory_batch_edit` — Destructive — https://policylayer.com/tools/io-github-vmoranv-jshookmcp/memory-batch-edit.md
- `memory_scan_session` — Destructive — https://policylayer.com/tools/io-github-vmoranv-jshookmcp/memory-scan-session.md
- `memory_unregister_type` — Destructive — https://policylayer.com/tools/io-github-vmoranv-jshookmcp/memory-unregister-type.md
- `nemu_destroy_session` — Destructive — https://policylayer.com/tools/io-github-vmoranv-jshookmcp/nemu-destroy-session.md
- `page_cookies` — Destructive — https://policylayer.com/tools/io-github-vmoranv-jshookmcp/page-cookies.md
- `page_local_storage` — Destructive — https://policylayer.com/tools/io-github-vmoranv-jshookmcp/page-local-storage.md
- `page_session_storage` — Destructive — https://policylayer.com/tools/io-github-vmoranv-jshookmcp/page-session-storage.md
- `proxy_clear_logs` — Destructive — https://policylayer.com/tools/io-github-vmoranv-jshookmcp/proxy-clear-logs.md
- `proxy_clear_rules` — Destructive — https://policylayer.com/tools/io-github-vmoranv-jshookmcp/proxy-clear-rules.md
- `proxy_remove_rule` — Destructive — https://policylayer.com/tools/io-github-vmoranv-jshookmcp/proxy-remove-rule.md
- `reset_token_budget` — Destructive — https://policylayer.com/tools/io-github-vmoranv-jshookmcp/reset-token-budget.md
- `session_progress_clear` — Destructive — https://policylayer.com/tools/io-github-vmoranv-jshookmcp/session-progress-clear.md
- `snapshot_restore` — Destructive — https://policylayer.com/tools/io-github-vmoranv-jshookmcp/snapshot-restore.md
- `tls_keylog_seal` — Destructive — https://policylayer.com/tools/io-github-vmoranv-jshookmcp/tls-keylog-seal.md
- `v8_heap_snapshot_delete` — Destructive — https://policylayer.com/tools/io-github-vmoranv-jshookmcp/v8-heap-snapshot-delete.md
- `webhook` — Destructive — https://policylayer.com/tools/io-github-vmoranv-jshookmcp/webhook.md
- `activate_tools` — Execute — https://policylayer.com/tools/io-github-vmoranv-jshookmcp/activate-tools.md
- …and 705 more: https://policylayer.com/tools/io-github-vmoranv-jshookmcp.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=io-github-vmoranv-jshookmcp · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/io-github-vmoranv-jshookmcp
