Medium Risk

telora_product_issue

Task tracking: manage issues (tasks, bugs, context groups) within deliveries. Issues flow through To Do -> In Progress -> Done. Context groups organize related tasks with shared files and AI context. Actions: list issues (by delivery or product-wide), create an issue (title + deliveryId), update ...

Risk signalsHigh parameter count (17 properties)

Part of the Mcp Products server.

telora_product_issue can modify Mcp Products data, with no limits today. PolicyLayer puts allow, deny, and rate-limit rules on every call. Live in minutes.

SECURE MCP PRODUCTS →

Free to start. No card required.

AI agents use telora_product_issue to create or modify resources in Mcp Products. Write operations carry medium risk because an autonomous agent could trigger bulk unintended modifications. Rate limits prevent a single agent session from making hundreds of changes in rapid succession. Argument validation ensures the agent passes expected values.

Without a policy, an AI agent could call telora_product_issue repeatedly, creating or modifying resources faster than any human could review. PolicyLayer's rate limiting ensures write operations happen at a controlled pace, and argument validation catches malformed or unexpected inputs before they reach Mcp Products.

Write tools can modify data. A rate limit prevents runaway bulk operations from AI agents.

policy.json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "telora_product_issue": {
      "limits": [
        {
          "counter": "telora_product_issue_rate",
          "window": "minute",
          "max": 30,
          "scope": "grant"
        }
      ]
    }
  }
}

See the full Mcp Products policy for all 14 tools.

Get this rule live on your own Mcp Products server in minutes. PolicyLayer enforces it on every call, before it runs.

ENFORCE ON MY MCP PRODUCTS →

View all 14 tools →

These attack patterns abuse exactly the kind of access telora_product_issue gives an agent. Each links to the full case and the policy that stops it:

Browse the full MCP Attack Database →

Every attack above starts with a tool call. PolicyLayer checks each one against your policy first, so telora_product_issue only ever does what you allow.

SECURE MCP PRODUCTS →

Other write tools across the catalogue. The same approach applies to each: rate-limit and validate the arguments.

What does the telora_product_issue tool do? +

Task tracking: manage issues (tasks, bugs, context groups) within deliveries. Issues flow through To Do -> In Progress -> Done. Context groups organize related tasks with shared files and AI context. Actions: list issues (by delivery or product-wide), create an issue (title + deliveryId), update issue fields (status, priority, description), delete an issue. List responses include a 1-based index on each item (response-local; recomputed per call).. It is categorised as a Write tool in the Mcp Products MCP Server, which means it can create or modify data. Consider rate limits to prevent runaway writes.

How do I enforce a policy on telora_product_issue? +

Register the Mcp Products MCP server in PolicyLayer and add a rule for telora_product_issue: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches Mcp Products. Nothing to install.

What risk level is telora_product_issue? +

telora_product_issue is a Write tool with medium risk. Write tools should be rate-limited to prevent accidental bulk modifications.

Can I rate-limit telora_product_issue? +

Yes. Add a rate_limit block to the telora_product_issue rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.

How do I block telora_product_issue completely? +

Set action: deny in the PolicyLayer policy for telora_product_issue. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.

What MCP server provides telora_product_issue? +

telora_product_issue is provided by the Mcp Products MCP server (@telora/mcp-products). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.

Enforce policy on every Mcp Products tool call.

Deterministic rules across all 14 Mcp Products tools. Per-identity grants. Full audit log. Live in minutes. Nothing to install.

Free to start. No card required.

4,600+ MCP servers and 31,000+ tools scanned and risk-classified.

// GET IN TOUCH

Have a question or want to learn more? Send us a message.

Message sent.

We'll get back to you soon.