Silent Door Repository Handoff Planner
Server Details
Choose files for an agent handoff using filename decisions. No file contents or credentials.
- Status
- Healthy
- Last Tested
- Transport
- Streamable HTTP · MCP 2025-06-18
- URL
TDQS
Scored across 2 tools
prepare_repository_handoff has a concrete, well-specified job (produce include/exclude/skip indexes), but repository_safety_preflight is described only as a 'zero-effect path-metadata preflight' that 'never sends' things, giving no signal about what it actually computes or returns. The two clearly overlap in the repository-path/safety space, and an agent cannot reliably predict when to pick preflight over handoff.
Both names use snake_case, which is consistent at the character level, but the structural patterns diverge: 'prepare_<noun>' (verb-first) versus '<noun>_<noun>_<noun>' (noun-phrase, no clear verb). Readable but not a predictable verb_noun convention.
Two tools for a narrow, single-purpose server is defensible but thin; there is no way to inspect, list, or re-run anything, so the surface feels minimal even for the stated scope.
The handoff planner covers selection with indexes, but the second tool's behavior and outputs are unspecified, leaving an unclear boundary between the two. With no tool for enumerating candidate files, validating paths, or applying/confirming a plan, an agent hits dead ends beyond the single planning call.
Available Tools
2 toolsprepare_repository_handoffARead-onlyIdempotentInspect
Prepare a filename-only repository handoff plan from relative paths and file kinds. Use when asked to select files for another agent or reviewer. Returns exact zero-based include/exclude/skip indexes and reasons; map these back to the original input, never guess. Excludes known sensitive filenames and symlinks, skips directories. NOT a content security scan or permission to upload. No credentials or payment. Do not call for general advice or to claim that file contents are safe. Never send contents, secrets, repository URLs, archives or callbacks.
| Name | Required | Description | Default |
|---|---|---|---|
| entries | Yes |
Output Schema
| Name | Required | Description |
|---|---|---|
| schema | Yes | |
| skipIndexes | Yes | |
| entryDecisions | Yes | |
| excludeIndexes | Yes | |
| includeIndexes | Yes | |
| manifestDigest | Yes | |
| entriesReceived | Yes | |
| contentSecurityVerified | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnly, idempotent, non-destructive and closed-world, and the description does not contradict them. It adds real behavioral detail beyond the annotations: sensitive filenames and symlinks are excluded, directories are skipped, and results are zero-based include/exclude/skip indexes with reasons that must be mapped back to input. Only minor gaps (e.g. pagination/limits) remain.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Purpose is front-loaded in the first sentence and the rest is mostly load-bearing routing and safety constraints. Slightly dense with overlapping prohibitions ('No credentials or payment' / 'Never send contents, secrets...') that could be consolidated, but nothing is egregiously wasteful.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With an output schema present, return values need not be spelled out, and annotations carry the safety profile. The description still covers scope, exclusions, index-mapping semantics and explicit non-goals, leaving little an agent would need to guess for a single-parameter tool.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 0%, so the description must compensate. It clarifies that paths are relative and supplies the concept of 'file kinds' (matching path/kind), and mentions symlinks/directories behavior, but does not enumerate the kind enum values or the 512/1024 limits. Partial compensation for a low-coverage schema.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb (prepare), resource (repository handoff plan) and scope (filename-only, from relative paths and file kinds). It also distinguishes itself from the sibling repository_safety_preflight by explicitly declaring 'NOT a content security scan', so an agent can route correctly.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Gives a positive trigger ('Use when asked to select files for another agent or reviewer') and multiple explicit exclusions ('Do not call for general advice', 'to claim that file contents are safe', 'permission to upload'). When-to-use and when-not-to-use are both covered without inference.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
repository_safety_preflightCInspect
Zero-effect repository path-metadata preflight. Never send contents, archives, URLs, callbacks, or secrets.
| Name | Required | Description | Default |
|---|---|---|---|
| entries | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full behavioral burden. It usefully declares zero side effects and explicitly lists data categories never transmitted (contents, archives, URLs, callbacks, secrets), but it does not explain what the tool reads, how it behaves on invalid input, or what it returns.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two short sentences with no filler, front-loading the core identity before the safety constraints. It is efficient, though arguably under-specified rather than optimally concise.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a tool with a nested parameter schema, no output schema, and no annotations, the description is too sparse. It omits invocation semantics, return behavior, and sibling differentiation, leaving the agent with insufficient context to call it confidently.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 0%, so the description must compensate. 'Path-metadata' loosely hints at the entries array, but it does not explain the required path+kind object structure, the allowed kind enum values, or the 1024-item limit.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description names a resource ('repository path-metadata') and a mode ('preflight'), but the verb is implicit and the overall function remains vague. It partially restates the tool name rather than clearly stating what operation is performed or what a preflight returns.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
There is no guidance on when to use this tool versus the sibling prepare_repository_handoff, nor are prerequisites or exclusions stated. The negative constraints ('Never send...') are safety rules, not usage routing.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
2 tool updates
- First observed
prepare_repository_handoff - First observed
repository_safety_preflight
Related MCP Connectors
- uploads.shOAuthsh.uploads
Host files from coding agents; stage on a branch and attach to GitHub PRs.
Securely search and manage workspace context files for AI agents and teams.
File uploads for AI agents. Upload, list, and manage files. No signup required.
Compiles source-agent outputs into validated, receiver-ready handoff packages.
Related MCP Servers
AlicenseAqualityBmaintenanceEnables AI agents to safely interact with local files by enforcing policies that allow, block, or require approval for actions, while protecting credentials and maintaining a tamper-proof audit log.122MIT- FlicenseAqualityBmaintenanceEnables agents to price, send, and track encrypted file transfers, with files chunked, encrypted, and hashed locally before any network relay, and to retrieve signed collection receipts. It supports prepaid credit pools and gives agents a privacy-first transfer capability within their own trust domain.1-
- FlicenseNot gradedqualityBmaintenanceEnables AI agents to safely read and write files in a sandboxed workspace via natural language, with on-demand connection, CVE-hardened path confinement, injection resistance, and full audit logging.-
- AlicenseNot gradedqualityBmaintenanceEnables AI agents to interact with Nextcloud files only through human-approved, time-limited grants, with mandatory audit logging and no standing content access.GPL 3.0
Glama MCP Gateway
Add one secure layer between your agents and this server.