Skip to main content
Glama

TunnelMind Data API

ghostroute_ct_alerts

Returns the durable, deduplicated ledger of CT equivocation events the GhostRoute witness worker detects and pushes — a tree_size_rewind (an append-only log shrank), a root_fork (one tree_size witnessed with two different Merkle roots = a split-view log), or an sth_signature_invalid (a log's latest Signed Tree Head failed signature verification). Where /v1/ghostroute/witness shows live computed health, this is the immutable first-detection log: each entry's detected_at is when TunnelMind first raised the alarm. A healthy CT ecosystem returns an empty feed — any row here is a serious trust event.

Use this tool when:

  • You want a chronological record of CT trust violations, not live state.

  • You're polling for new equivocation events (check summary.last_detected_at).

Inputs:

  • limit (query, optional): max recent alerts, 1–200, default 50.

Returns:

  • summary: total, undelivered, rewinds, forks, bad_signatures, last_detected_at.

  • alerts[]: each kind, severity, log_url, log_operator, from_tree_size, to_tree_size, distinct_roots, event_observed_at, detected_at, delivered.

Latency:

  • Typical <200ms (KV-cached 1m).

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
limitNo

TDQS

A4.6/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations provided, the description carries the full burden and does well: it discloses durability, deduplication, immutability ('immutable first-detection log'), the meaning of an empty feed ('healthy CT ecosystem returns an empty feed'), and latency (KV-cached 1m, typical <200ms). However, it does not explicitly state read-only semantics or mention auth/rate limits, though the phrasing implies a read operation.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is moderately long but well-structured: purpose, usage, inputs, returns, latency. It is front-loaded with the core purpose and every section earns its place. It could be tightened slightly, but the structure aids comprehension.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given there is no output schema, the description thoroughly covers the return shape: both the summary fields (total, undelivered, rewinds, forks, bad_signatures, last_detected_at) and the alerts array fields (kind, severity, log_url, log_operator, from_tree_size, to_tree_size, distinct_roots, event_observed_at, detected_at, delivered). It also explains event semantics and latency, making it complete for an agent to select and invoke the tool.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The schema provides only a parameter named 'limit' with numeric constraints and no description (0% schema coverage). The description compensates by explaining 'limit (query, optional): max recent alerts, 1–200, default 50.' This adds the semantic meaning of limiting recent alerts, which is exactly what the schema lacks.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description opens with a specific verb and resource: 'Returns the durable, deduplicated ledger of CT equivocation events.' It enumerates exact event kinds (tree_size_rewind, root_fork, sth_signature_invalid) and explicitly contrasts with '/v1/ghostroute/witness' (live computed health), clearly distinguishing itself from the sibling ghostroute_ct_witness tool.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description provides explicit 'Use this tool when' bullets: for a chronological record of CT trust violations and for polling new events (check summary.last_detected_at). It also implies when not to use it by stating it is 'not live state' and referencing the witness endpoint for live health. This gives clear contextual guidance and an alternative.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

TDQS

B3.3/5.0
Disambiguation2/5

Many tools overlap in purpose, such as cross_lens_verify, cross_lens_lookup, profile_entity, and preflight_should_i_act, which all return node verdicts with subtle differences. Sigil verification tools and receipt-related tools also have similar names and require deep reading to distinguish.

Naming Consistency3/5

The tool names are mostly readable, but the pattern is mixed: some use verb_noun (get_domain, create_subscription) while others use domain prefixes (sigil_*, ghostroute_*, intel_*). Within each domain, naming is consistent, but the overall style lacks uniformity.

Tool Count1/5

With 90 tools, this server is extremely overloaded. Even for a multi-purpose data API, the sheer number overwhelms and makes navigation difficult, far exceeding the typical well-scoped MCP server. The count is an extreme mismatch for the apparent scope.

Completeness4/5

The tool surface is very comprehensive, covering tracker lookup, cross-lens verification, receipts, compliance, subscriptions, tasks, intel probes, and more. Minor gaps exist, such as no batch cross-lens verification, but core workflows are well covered.

Resources