Skip to main content
Glama

Helvabase — Governed response dossiers

helvabase_upload_original

Idempotent

Store actual bytes of one explicitly selected, manifest-authorized production original (max 1 MiB). Requires enabled retention policy. This does not ingest or approve the file. Never use a local path or invent bytes. Original remains unchanged; future filling creates a separate version.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
formatYes
sourceIdYes
projectIdYesHelvabase project/mapping ID returned by list or create dossier, never a local path.
manifestIdYes
contentBase64Yes
idempotencyKeyYesUnique key for this logical mutation. Reuse exactly the same key and arguments after a timeout; never generate a new key to force a replay.
transferAuthorizedYes

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

A4.3/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Beyond the annotations (non-readonly, idempotent, non-destructive), the description discloses a hard size cap (1 MiB), a precondition (enabled retention policy), a scope boundary (no ingestion or approval), and versioning semantics ('Original remains unchanged; future filling creates a separate version'). That is meaningful behavioral context an agent cannot get from the structured fields.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Four tight sentences with the core action front-loaded and each subsequent sentence adding a distinct constraint (size, precondition, boundary, versioning). No filler, though the cadence is slightly list-like rather than polished prose.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a 7-required-param mutation with low schema coverage and no output schema, the description covers preconditions, limits, and consequences well. It leaves format/transferAuthorized semantics unexplained, but the critical operational facts an agent needs to call it correctly are present.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is only 29%, so the description must carry the burden and only partially does: it implies manifest-authorized (manifestId), a single selected original (sourceId) and the byte cap (contentBase64 size), but says nothing about format, transferAuthorized, or the idempotency semantics. Partial compensation, not full.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource (store the actual bytes of a production original) plus precise scope qualifiers (one, explicitly selected, manifest-authorized, max 1 MiB). The sentence 'This does not ingest or approve the file' explicitly separates it from approval/ingestion siblings such as the various confirm/apply tools.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives real preconditions ('Requires enabled retention policy') and explicit exclusions ('does not ingest or approve', 'never use a local path or invent bytes'). It stops short of naming a sibling alternative (e.g., upload_sources or cancel_source_upload) the way a 5 would, but the when/when-not guidance is clear.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.