AI agents use monday-add-doc-block to create or update resources in @mcp Server Monday — usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your @mcp Server Monday environment.
This tool creates or modifies document content reversibly. Users can add blocks (text, images, tables, etc.) to documents, which is a Write operation. While the action is reversible (blocks can be removed), it does modify the document's state.
From the tool's definition Tool name and description: 'Add a block to an existing document' indicates creation/modification of document content. The verb 'Add' combined with 'block' in a document context means inserting new structured content into an existing document.
Risk signalsModifies shared documents
Documented attack patterns abuse exactly the kind of access monday-add-doc-block gives an agent:
PolicyLayer is an MCP gateway — it sits between your AI agents and @mcp Server Monday, and nothing reaches the server without passing your rules. This is the rule we recommend for monday-add-doc-block:
{
"version": "1",
"default": "deny",
"tools": {
"monday-add-doc-block": {
"limits": [
{
"counter": "monday-add-doc-block_rate",
"window": "minute",
"max": 30,
"scope": "grant"
}
]
}
}
} monday-add-doc-block stays usable, but capped — an agent stuck in a loop can't make hundreds of changes a minute. Everything else on the server is denied unless you say otherwise.
Free to start. No card required.
Add a block to an existing document. It is categorised as a Write tool in the @mcp Server Monday MCP Server, which means it can create or modify data. Consider rate limits to prevent runaway writes.
Register the @mcp Server Monday MCP server in PolicyLayer and add a rule for monday-add-doc-block: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches @mcp Server Monday. Nothing to install.
monday-add-doc-block is a Write tool with medium risk. Write tools should be rate-limited to prevent accidental bulk modifications.
Yes. Add a rate_limit block to the monday-add-doc-block rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for monday-add-doc-block. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
monday-add-doc-block is provided by the @mcp Server Monday MCP server (@mcp-server-monday). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
Start from @mcp Server Monday, add the rest of your stack, and see everything your agents can call. Then put policy on all of it.
Free to start. No card required.
16 @mcp Server Monday tools catalogued and risk-classified — across an index of 43,000+ MCP servers.