High Risk →

preview_scrape

Preview what pages would be scraped without actually downloading content. This is a dry-run mode that helps you: - Verify the correct pages will be scraped - Check if llms.txt is detected - Validate CSS selectors before actual scraping - Estimate the scope of a scraping operation Returns a list o...

Part of the MarkGrab server.

preview_scrape can trigger actions in MarkGrab, with no limits today. PolicyLayer puts allow, deny, and rate-limit rules on every call. Live in minutes.

SECURE MARKGRAB →

Free to start. No card required.

AI agents invoke preview_scrape to trigger processes or run actions in MarkGrab. Execute operations can have side effects beyond the immediate call -- triggering builds, sending notifications, or starting workflows. Rate limits and argument validation are essential to prevent runaway execution.

preview_scrape can trigger processes with real-world consequences. An uncontrolled agent might start dozens of builds, send mass notifications, or kick off expensive compute jobs. PolicyLayer enforces rate limits and validates arguments to keep execution within safe bounds.

Execute tools trigger processes. Rate-limit and validate arguments to prevent unintended side effects.

policy.json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "preview_scrape": {
      "limits": [
        {
          "counter": "preview_scrape_rate",
          "window": "minute",
          "max": 10,
          "scope": "grant"
        }
      ]
    }
  }
}

See the full MarkGrab policy for all 5 tools.

Get this rule live on your own MarkGrab server in minutes. PolicyLayer enforces it on every call, before it runs.

ENFORCE ON MY MARKGRAB →

These attack patterns abuse exactly the kind of access preview_scrape gives an agent. Each links to the full case and the policy that stops it:

Browse the full MCP Attack Database →

Every attack above starts with a tool call. PolicyLayer checks each one against your policy first, so preview_scrape only ever does what you allow.

SECURE MARKGRAB →

Other execute tools across the catalogue. The same approach applies to each: rate-limit and validate the arguments.

What does the preview_scrape tool do? +

Preview what pages would be scraped without actually downloading content. This is a dry-run mode that helps you: - Verify the correct pages will be scraped - Check if llms.txt is detected - Validate CSS selectors before actual scraping - Estimate the scope of a scraping operation Returns a list of all pages that would be scraped along with configuration details.. It is categorised as a Execute tool in the MarkGrab MCP Server, which means it can trigger actions or run processes. Use rate limits and argument validation.

How do I enforce a policy on preview_scrape? +

Register the MarkGrab MCP server in PolicyLayer and add a rule for preview_scrape: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches MarkGrab. Nothing to install.

What risk level is preview_scrape? +

preview_scrape is a Execute tool with high risk. Execute tools should be rate-limited and have argument validation enabled.

Can I rate-limit preview_scrape? +

Yes. Add a rate_limit block to the preview_scrape rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.

How do I block preview_scrape completely? +

Set action: deny in the PolicyLayer policy for preview_scrape. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.

What MCP server provides preview_scrape? +

preview_scrape is provided by the MarkGrab MCP server (pypi:markgrab). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.

Enforce policy on every MarkGrab tool call.

Deterministic rules across all 5 MarkGrab tools. Per-identity grants. Full audit log. Live in minutes. Nothing to install.

Free to start. No card required.

4,600+ MCP servers and 31,000+ tools scanned and risk-classified.

// GET IN TOUCH

Have a question or want to learn more? Send us a message.

Message sent.

We'll get back to you soon.