Skip to main content
Glama

AxioRank: Zero-Trust for AI Agents

Get incident kill-chain evidence

axiorank_get_incident
Read-onlyIdempotent

Fetch the kill-chain finding behind an alert (the multi-step attack pattern, severity, and the contributing tool-call ids) by alert id. Returns null evidence for a non-kill-chain alert. Requires the logs:read scope.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
alertIdYesThe alert/incident UUID (from axiorank_list_incidents).

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

A4.2/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint, idempotentHint, and destructiveHint. The description adds beyond that: returns null for non-kill-chain alerts and requires a specific scope. This provides useful context about edge cases and permissions, though it omits details like rate limits or error handling.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two sentences: first concisely defines the purpose and output, second adds an edge case and required scope. No fluff, front-loaded with the core action. Every sentence earns its place.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With a single parameter, no output schema, and annotations covering safety, the description fairly explains the return (null for non-kill-chain) and mentions the output shape (pattern, severity, tool-call ids). It could be enhanced by describing the response structure more, but overall it's sufficient for a simple, read-only fetch.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the schema already describes the alertId parameter as a UUID from list_incidents. The description does not add any extra semantics or usage guidance beyond what the schema provides. Baseline 3 is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the action (fetch kill-chain finding), the resource (alert), and the key details returned (multi-step attack pattern, severity, tool-call ids). It distinguishes from siblings like axiorank_list_incidents by focusing on evidence retrieval. The note about null evidence for non-kill-chain alerts adds precision.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description explicitly requires an alert ID and the `logs:read` scope, which guides invocation. It implicitly suggests use when kill-chain details are needed, but does not provide explicit when-not-to-use or mention alternative tools like list_incidents. Given sibling names, the context is clear enough.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources