Skip to main content
Glama

Helvabase — Governed response dossiers

helvabase_confirm_review

Idempotent

Record the reviewer's explicit confirmation using the one-time code THEY supplied after inspecting this exact revision. Never invent, search for or read the code from their mailbox. Old revisions, changed sources, expired codes and replays are rejected. This records email-confirmed authorization, not a legal electronic signature.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
codeYes
revisionYes
challengeIdYes
idempotencyKeyYesUnique key for this logical mutation. Reuse exactly the same key and arguments after a timeout; never generate a new key to force a replay.

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

A3.7/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations only declare the mutation/idempotency profile; the description adds real behavioral substance — old revisions, changed sources, expired codes and replays are rejected, and the scope is explicitly 'email-confirmed authorization, not a legal electronic signature'. It stops short of describing what a successful call returns or what happens to the revision afterward.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Three dense sentences, front-loaded with the core action and followed by constraints and scope. Every sentence carries information; the only mild weakness is that the prohibition about reading the mailbox and the rejection list are packed tightly without prioritization.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a four-required-parameter mutation with a nested revision object, no output schema, and annotations already covering the safety profile, the description supplies the critical prerequisites (one-time code provenance, revision match, rejection conditions). The missing pieces — challengeId meaning and post-call outcome — are secondary.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 25% (only idempotencyKey is documented in the schema). The description adds genuine semantics for 'code' (one-time, reviewer-supplied, never retrieved from the mailbox) and gestures at 'revision' ('this exact revision'), but 'challengeId' — a required parameter — is never explained, leaving a notable gap.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb (record) and resource (the reviewer's explicit confirmation), plus the mechanism (one-time code supplied by the reviewer). It does not name any of the many confirm_* siblings (confirm_document_review, confirm_pack_review, etc.) to distinguish which 'review' this covers, so an agent must infer the scope from the resource name alone.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Usage is implied rather than stated: the code must come from the reviewer 'after inspecting this exact revision', and an agent is told never to fetch it from the mailbox. There is no explicit statement of when to call this versus initiating a review via request_review or one of the other confirm_* tools, so routing is left to inference.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.