copy_asset_with_dependencies
Copy a project asset and its full dependency closure (via Asset.GetReferences(deep:true)) into a target directory, preserving relative path structure so material references to textures keep resolving. SHADOW GUARD: refuses to write under core engine trees (models/citizen, models/dev, materials/de...
This record as markdown: /tools/sbox/copy-asset-with-dependencies.md
What copy_asset_with_dependencies does on Sbox
AI agents use copy_asset_with_dependencies to create or update resources in Sbox, usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your Sbox environment.
Why copy_asset_with_dependencies is rated Medium
This tool creates or modifies data by copying assets into target directories. While it has protective guards (SHADOW GUARD) preventing writes to core engine trees, the core action is file duplication/creation rather than deletion or irreversible destruction. The copies can be removed or overwritten, making it Write rather than Destructive.
From the tool's definition Tool description explicitly states it "Copy a project asset and its full dependency closure into a target directory, preserving relative path structure." The function copies files and their dependencies into new locations, which are reversible modifications.
Attacks that exploit this kind of access
The rule that runs copy_asset_with_dependencies safely
PolicyLayer is an MCP gateway: it sits between your AI agents and Sbox, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For copy_asset_with_dependencies, this is the rule to start with:
copy_asset_with_dependencies stays usable, but capped: an agent stuck in a loop can't make hundreds of changes a minute. Everything else on the server is denied unless you say otherwise.
The button opens the PolicyLayer dashboard: create your workspace, connect Sbox, apply this rule, and every copy_asset_with_dependencies call is checked against it from then on.
Questions about copy_asset_with_dependencies
Copy a project asset and its full dependency closure (via Asset.GetReferences(deep:true)) into a target directory, preserving relative path structure so material references to textures keep resolving. SHADOW GUARD: refuses to write under core engine trees (models/citizen, models/dev, materials/dev, materials/default) -- copying there triggers an infinite asset-recompile loop (BRIDGE_GOTCHAS #5). Cloud/procedural/transient assets are skipped with a reason. Returns { copied:[{from,to}], skipped:[{path,reason}], count, note }. It is categorised as a Write tool in the Sbox MCP Server, which means it can create or modify data. Consider rate limits to prevent runaway writes.
Register the Sbox MCP server in PolicyLayer and add a rule for copy_asset_with_dependencies: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches Sbox. Nothing to install.
copy_asset_with_dependencies is a Write tool with medium risk. Write tools should be rate-limited to prevent accidental bulk modifications.
Yes. Add a rate_limit block to the copy_asset_with_dependencies rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for copy_asset_with_dependencies. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
copy_asset_with_dependencies is provided by the Sbox MCP server (sbox-mcp-server). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on Sbox, and thousands of servers like it.
This server
Across the catalogue