Skip to main content
Glama

Count subdomains

count_subdomains
Read-onlyIdempotent

Return only the total number of distinct subdomains known for a domain — no list. Cheap and low-token. Use when the user asks "how many subdomains" or you only need the size of the attack surface. Count includes historic subdomains that may no longer be live. It is a point-in-time figure that changes over time, so treat it as current-as-of-query, not a fixed value.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
domainYesRoot (registrable) domain as a bare hostname, e.g. "example.com". No scheme, path, port, or leading "www." — these are stripped.

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
totalYesTotal distinct subdomains known.
domainYes

TDQS

A4.5/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already cover read-only and idempotent hints, so the description adds valuable context beyond that: it mentions 'cheap and low-token', includes historic subdomains that may no longer be live, and emphasizes that the count is a point-in-time figure that changes over time. These are important behavioral nuances not present in the structured fields.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is four sentences long, each earning its place: the first states the core purpose, the second adds cost/performance, the third gives usage guidance, and the last two provide essential caveats. It is front-loaded with the most important information and contains no fluff.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

The tool is simple (one parameter) and the output schema exists, so the description doesn't need to explain return values. It covers what the tool returns, when to use it, cost/latency characteristics, and important caveats (historical data, point-in-time). With the sibling tool listed for contrast, the description is complete for an agent to select and invoke correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, and the schema already explains the domain parameter thoroughly (bare hostname, no scheme/path/port/www). The description adds no additional parameter semantics beyond what the schema provides, so a baseline score of 3 is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a specific verb and resource: 'Return only the total number of distinct subdomains known for a domain — no list.' This clearly distinguishes it from the sibling tool find_subdomains, which presumably returns a list, by emphasizing the count-only behavior.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description explicitly says when to use it: 'Use when the user asks "how many subdomains" or you only need the size of the attack surface.' It does not explicitly name alternatives or when-not-to-use, but the contrast with 'no list' and the presence of the sibling find_subdomains provide clear context for differentiating usage.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

TDQS

A4.6/5.0
Disambiguation5/5

The two tools have clearly distinct purposes: one returns a count, the other returns a list. The descriptions explicitly highlight when to use each (e.g., 'how many subdomains' vs 'list them'), eliminating ambiguity.

Naming Consistency5/5

Both tools follow the same verb_noun pattern with snake_case: count_subdomains and find_subdomains. The naming is consistent, predictable, and aligns with the server's domain.

Tool Count4/5

With only two tools, the set is minimal but well-suited to the narrow purpose of passive subdomain enumeration. While it falls below the typical 3-15 range, the scope is so focused that two tools adequately cover the core functionality.

Completeness5/5

The tool set covers both main operations for the domain: getting a count and listing subdomains. The descriptions mention pagination/truncation for the list, but no other obvious operations are missing for the stated use cases (recon, inventory, etc.).

Resources