listArchitectureIcons
SOFTWARE & CLOUD architecture icons ONLY (AWS, Azure, GCP, Docker, Kubernetes, databases, message queues, dev tools, etc.). This catalog has NO general/nature/science/people/business icons — so for any NON-technical topic (e.g. photosynthesis, biology, history, marketing), do NOT use this tool; i...
This record as markdown: /tools/io-stablebaseline-sb/listarchitectureicons.md
What listArchitectureIcons does on Stable Baseline
AI agents call listArchitectureIcons to retrieve information from Stable Baseline without modifying anything. It is typically the context-gathering step in research, monitoring, and reporting workflows, before the agent takes action elsewhere.
| Parameter | Type | Required | Description |
|---|---|---|---|
limit | number | — | |
query | string | — | Search by name, category, vendor, or description. |
fields | array | — | Field projection. Valid fields: id, iconPath, iconName, category, subcategory, vendor, description, searchTerms, tags, useCases, aliases, isFeatured, displayOrd |
offset | number | — | |
category | string | — | Filter by category (e.g. AWS, Azure, GCP, dev, essentials). |
Parameters from the server's own tool schema.
Why listArchitectureIcons is rated Low
This tool retrieves and lists pre-existing architecture icon resources in response to queries. It performs a read-only lookup operation against a catalog, with no capability to modify, delete, create, or execute any operations. The description confirms it is a passive retrieval mechanism ('it returns nothing for off-domain queries').
From the tool's definition Tool name is 'listArchitectureIcons' and description states it 'returns' a catalog of architecture icons with `iconPath` results. It explicitly retrieves/queries data from an icon catalog with no side effects mentioned.
Attacks that exploit this kind of access
The rule that runs listArchitectureIcons safely
PolicyLayer is an MCP gateway: it sits between your AI agents and Stable Baseline, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For listArchitectureIcons, this is the rule to start with:
listArchitectureIcons is read-only, so it stays allowed. Everything else on the server is denied unless you say otherwise.
The button opens the PolicyLayer dashboard: create your workspace, connect Stable Baseline, apply this rule, and every listArchitectureIcons call is checked against it from then on.
Questions about listArchitectureIcons
SOFTWARE & CLOUD architecture icons ONLY (AWS, Azure, GCP, Docker, Kubernetes, databases, message queues, dev tools, etc.). This catalog has NO general/nature/science/people/business icons — so for any NON-technical topic (e.g. photosynthesis, biology, history, marketing), do NOT use this tool; instead put a relevant emoji directly in the element's label (e.g. ☀️ Sunlight, 💧 Water, 🌿 Leaf). It returns nothing for off-domain queries by design — never force an unrelated tech logo onto a non-tech concept. Each result has an iconPath (e.g. 'dev/docker.svg'). TWO ways to use it: (1) on a WHITEBOARD, drop it via addWhiteboardElements({ type:'image', iconPath:'dev/docker.svg', x, y, width:96, height:96, text:'Docker' }); (2) in a D2 systems-architecture diagram, use the iconPath as-is in D2 code (e.g. icon: dev/docker.svg). It is categorised as a Read tool in the Stable Baseline MCP Server, which means it retrieves data without modifying state.
listArchitectureIcons accepts 5 parameters: limit, query, fields, offset, category. The full parameter table on this page comes from the server's own tool schema.
Register the Stable Baseline MCP server in PolicyLayer and add a rule for listArchitectureIcons: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches Stable Baseline. Nothing to install.
listArchitectureIcons is a Read tool with low risk. Read-only tools are generally safe to allow by default.
Yes. Add a rate_limit block to the listArchitectureIcons rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for listArchitectureIcons. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
listArchitectureIcons is provided by the Stable Baseline MCP server (https://api.stablebaseline.io/functions/v1/cloud-serve/mcp). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on Stable Baseline, and thousands of servers like it.
This server
Across the catalogue