detect_file_relationships
Auto-detect tasks that modify the same files and create modifies_same_file relationships.
This record as markdown: /tools/todos/detect-file-relationships.md
What detect_file_relationships does on Todos
AI agents use detect_file_relationships to create or update resources in Todos, usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your Todos environment.
Why detect_file_relationships is rated Medium
The tool actively creates new relationship records between tasks (modifies_same_file relationships), which is a Write operation. While it has a read component (detecting file overlap), its primary effect is creating new data in the task management system. Misuse could create spurious or incorrect dependency relationships affecting agent task coordination.
From the tool's definition 'Auto-detect tasks that modify the same files and create modifies_same_file relationships'
Attacks that exploit this kind of access
The rule that runs detect_file_relationships safely
PolicyLayer is an MCP gateway: it sits between your AI agents and Todos, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For detect_file_relationships, this is the rule to start with:
detect_file_relationships stays usable, but capped: an agent stuck in a loop can't make hundreds of changes a minute. Everything else on the server is denied unless you say otherwise.
The button opens the PolicyLayer dashboard: create your workspace, connect Todos, apply this rule, and every detect_file_relationships call is checked against it from then on.
Questions about detect_file_relationships
Auto-detect tasks that modify the same files and create modifies_same_file relationships. It is categorised as a Write tool in the Todos MCP Server, which means it can create or modify data. Consider rate limits to prevent runaway writes.
Register the Todos MCP server in PolicyLayer and add a rule for detect_file_relationships: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches Todos. Nothing to install.
detect_file_relationships is a Write tool with medium risk. Write tools should be rate-limited to prevent accidental bulk modifications.
Yes. Add a rate_limit block to the detect_file_relationships rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for detect_file_relationships. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
detect_file_relationships is provided by the Todos MCP server (@hasna/todos). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on Todos, and thousands of servers like it.
This server
Across the catalogue