onloon-explore-customs-data__runOperation
Phase 6 Agent Facade — 技能层统一入口(不新增 OpenAPI 路由)
This record as markdown: /tools/lxwl-mcp-server/onloon-explore-customs-data--runoperation.md
What onloon-explore-customs-data__runOperation does on Lxwl
AI agents call onloon-explore-customs-data__runOperation to retrieve information from Lxwl without modifying anything. It is typically the context-gathering step in research, monitoring, and reporting workflows, before the agent takes action elsewhere.
| Parameter | Type | Required | Description |
|---|---|---|---|
list | boolean | — | |
role | string | — | buyer=采购商,supplier=供应商,trader=贸易商。 |
input | object | — | 与指定 operation 的 input 一致;不要混用其他 operation 的字段。扁平字段必须与指定 operation 的 input 一致,禁止把别的 operation 的字段混进来 |
keyword | string | — | |
queryId | string | — | |
recordId | string | — | |
operation | string | — | 须带 customs. 前缀。listMerchants 等简称无效。 |
merchantId | string | — | |
searchType | string | — | productName=产品名,companyName=公司名,hsCode=海关编码。 |
companyName | string | — | |
countryCode | string | — | |
dataSourceCountry | string | — |
Parameters from the server's own tool schema.
Why onloon-explore-customs-data__runOperation is rated Low
Even though onloon-explore-customs-data__runOperation only reads data, uncontrolled read access leaks sensitive information and racks up API costs: an agent caught in a retry loop can make thousands of calls a minute without anyone noticing.
Risk signalsHigh parameter count (12 properties)
Attacks that exploit this kind of access
The rule that runs onloon-explore-customs-data__runOperation safely
PolicyLayer is an MCP gateway: it sits between your AI agents and Lxwl, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For onloon-explore-customs-data__runOperation, this is the rule to start with:
onloon-explore-customs-data__runOperation is read-only, so it stays allowed. Everything else on the server is denied unless you say otherwise.
The button opens the PolicyLayer dashboard: create your workspace, connect Lxwl, apply this rule, and every onloon-explore-customs-data__runOperation call is checked against it from then on.
Questions about onloon-explore-customs-data__runOperation
Phase 6 Agent Facade — 技能层统一入口(不新增 OpenAPI 路由). It is categorised as a Read tool in the Lxwl MCP Server, which means it retrieves data without modifying state.
onloon-explore-customs-data__runOperation accepts 12 parameters: list, role, input, keyword, queryId, recordId, operation, merchantId, searchType, companyName, countryCode, dataSourceCountry. The full parameter table on this page comes from the server's own tool schema.
Register the Lxwl MCP server in PolicyLayer and add a rule for onloon-explore-customs-data__runOperation: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches Lxwl. Nothing to install.
onloon-explore-customs-data__runOperation is a Read tool with low risk. Read-only tools are generally safe to allow by default.
Yes. Add a rate_limit block to the onloon-explore-customs-data__runOperation rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for onloon-explore-customs-data__runOperation. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
onloon-explore-customs-data__runOperation is provided by the Lxwl MCP server (@lxwl/mcp-server). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on Lxwl, and thousands of servers like it.
This server
Across the catalogue