Test various Graph API queries to discover hidden properties or endpoints for folder/group organization in Microsoft To Do.
AI agents invoke test-graph-api-exploration to trigger actions in My MCP. What it does depends on the arguments the agent supplies, and its effects often reach beyond the immediate call — builds kicked off, notifications sent, workflows started.
This tool actively executes Graph API queries to probe and discover endpoints/properties, which constitutes running external operations against a live API. It's not a simple read because it performs exploratory/discovery queries that could trigger unintended side effects or expose sensitive data. The 'discover hidden properties or endpoints' language indicates probing behavior beyond standard retrieval.
From the tool's definition "Test various Graph API queries" and "discover hidden properties or endpoints" — executes exploratory API calls against Microsoft Graph
Documented attack patterns abuse exactly the kind of access test-graph-api-exploration gives an agent:
PolicyLayer is an MCP gateway — it sits between your AI agents and My MCP, and nothing reaches the server without passing your rules. This is the rule we recommend for test-graph-api-exploration:
{
"version": "1",
"default": "deny",
"tools": {
"test-graph-api-exploration": {
"limits": [
{
"counter": "test-graph-api-exploration_rate",
"window": "minute",
"max": 10,
"scope": "grant"
}
]
}
}
} test-graph-api-exploration stays usable, but rate-capped — a runaway agent can't fire it dozens of times a minute. Everything else on the server is denied unless you say otherwise.
Free to start. No card required.
Test various Graph API queries to discover hidden properties or endpoints for folder/group organization in Microsoft To Do. It is categorised as a Execute tool in the My MCP MCP Server, which means it can trigger actions or run processes. Use rate limits and argument validation.
Register the My MCP server in PolicyLayer and add a rule for test-graph-api-exploration: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches My MCP. Nothing to install.
test-graph-api-exploration is a Execute tool with high risk. Execute tools should be rate-limited and have argument validation enabled.
Yes. Add a rate_limit block to the test-graph-api-exploration rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for test-graph-api-exploration. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
test-graph-api-exploration is provided by the My MCP server (jordanburke/microsoft-todo-mcp-server). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
Start from My MCP, add the rest of your stack, and see everything your agents can call. Then put policy on all of it.
Free to start. No card required.
16 My MCP tools catalogued and risk-classified — across an index of 43,000+ MCP servers.