AI agents call get_callers_callees to retrieve information from Repowise without modifying anything — typically the context-gathering step in research, monitoring, and reporting workflows, before the agent takes action elsewhere.
Despite an empty description, the naming convention and context strongly suggest this tool queries function/method call relationships within a codebase—a Read operation providing architectural intelligence. The 'get_' prefix and parallel tools confirm this is a retrieval-only capability. Low severity because reading code metadata poses minimal risk even if misused by an AI agent.
From the tool's definition Tool name 'get_callers_callees' indicates data retrieval (getter pattern); sibling tools like 'get_answer', 'get_architecture_diagram', 'get_context', and 'get_dependency_path' are all read-only intelligence layers that retrieve codebase information without…
Documented attack patterns abuse exactly the kind of access get_callers_callees gives an agent:
PolicyLayer is an MCP gateway — it sits between your AI agents and Repowise, and nothing reaches the server without passing your rules. This is the rule we recommend for get_callers_callees:
{
"version": "1",
"default": "deny",
"tools": {
"get_callers_callees": {}
}
} get_callers_callees is read-only, so it stays allowed — but everything else on the server is denied unless you say otherwise.
Free to start. No card required.
get_callers_callees. It is categorised as a Read tool in the Repowise MCP Server, which means it retrieves data without modifying state.
Register the Repowise MCP server in PolicyLayer and add a rule for get_callers_callees: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches Repowise. Nothing to install.
get_callers_callees is a Read tool with low risk. Read-only tools are generally safe to allow by default.
Yes. Add a rate_limit block to the get_callers_callees rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for get_callers_callees. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
get_callers_callees is provided by the Repowise MCP server (repowise-dev/repowise). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
Deterministic rules across all 19 Repowise tools. Per-identity grants. Full audit log. Live in minutes. Nothing to install.
Free to start. No card required.
19 Repowise tools catalogued and risk-classified — across an index of 42,500+ MCP servers.