High Risk →

turn_manage

Turn-based strategy game lifecycle (multi-agent coordination). 🎮 STRATEGY TURN CYCLE: 1. init - Initialize turn state (once per world) 2. get_status - Check current turn, phase, which nations ready 3. submit_actions - Submit batched actions (claims, alliances, diplomacy) 4. mark_ready - Signal p...

How to control turn_manage ↓

What turn_manage does on Rpg

AI agents invoke turn_manage to trigger actions in Rpg. What it does depends on the arguments the agent supplies, and its effects often reach beyond the immediate call — builds kicked off, notifications sent, workflows started.

High Risk

Why turn_manage needs a policy

This tool manages the lifecycle of multi-agent turn-based gameplay, including submitting and resolving actions that affect game state. Submitting actions and resolving turns triggers external operations (multi-agent coordination, automatic resolution) whose effects depend on arguments. It modifies persistent SQLite-backed game state and coordinates between agents, placing it in Execute.

From the tool's definition Turn-based strategy game lifecycle (multi-agent coordination); submit_actions - Submit batched actions (claims, alliances, diplomacy); Turn resolves automatically when ALL nations call mark_ready

Documented attack patterns abuse exactly the kind of access turn_manage gives an agent:

How to control turn_manage

PolicyLayer is an MCP gateway — it sits between your AI agents and Rpg, and nothing reaches the server without passing your rules. This is the rule we recommend for turn_manage:

policy.json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "turn_manage": {
      "limits": [
        {
          "counter": "turn_manage_rate",
          "window": "minute",
          "max": 10,
          "scope": "grant"
        }
      ]
    }
  }
}

turn_manage stays usable, but rate-capped — a runaway agent can't fire it dozens of times a minute. Everything else on the server is denied unless you say otherwise.

  1. Create a free account and register Rpg — nothing to install.
  2. Add this policy — paste it, or build it visually.
  3. Point your MCP client (Claude, Cursor, anything) at your gateway URL.
RATE-LIMIT THIS TOOL →

Free to start. No card required.

Related tools and policies

Go deeper

Questions about turn_manage

What does the turn_manage tool do? +

Turn-based strategy game lifecycle (multi-agent coordination). 🎮 STRATEGY TURN CYCLE: 1. init - Initialize turn state (once per world) 2. get_status - Check current turn, phase, which nations ready 3. submit_actions - Submit batched actions (claims, alliances, diplomacy) 4. mark_ready - Signal planning complete 5. poll_results - Get resolved turn events ⚔️ MULTI-AGENT PLAY: Each AI agent controls one nation. Turn resolves automatically when ALL nations call mark_ready. Use get_status to see who. It is categorised as a Execute tool in the Rpg MCP Server, which means it can trigger actions or run processes. Use rate limits and argument validation.

How do I enforce a policy on turn_manage? +

Register the Rpg MCP server in PolicyLayer and add a rule for turn_manage: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches Rpg. Nothing to install.

What risk level is turn_manage? +

turn_manage is a Execute tool with high risk. Execute tools should be rate-limited and have argument validation enabled.

Can I rate-limit turn_manage? +

Yes. Add a rate_limit block to the turn_manage rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.

How do I block turn_manage completely? +

Set action: deny in the PolicyLayer policy for turn_manage. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.

What MCP server provides turn_manage? +

turn_manage is provided by the Rpg MCP server (mnehmos/mnehmos.rpg.mcp). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.

Enforce policy on every Rpg tool call.

Start from Rpg, add the rest of your stack, and see everything your agents can call. Then put policy on all of it.

Free to start. No card required.

47 Rpg tools catalogued and risk-classified — across an index of 43,000+ MCP servers.

// GET IN TOUCH

Have a question or want to learn more? Send us a message.

Message sent.

We'll get back to you soon.