Skip to main content
Glama

MUJ428 Trust Reflex

trust_action
Read-onlyIdempotent

VERIFY BEFORE ACT across payments, purchases, delegation, approvals, writes, releases, commits, and other consequential actions. Returns ALLOW, VERIFY, REQUIRE_VERIFICATION, or DENY plus Trust Receipt v1.3; FREE_PREFLIGHT execution_authority=false and no funds are moved.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
actionYesAI-native action vocabulary.
evidenceNo
externalNo
milestoneNo
action_refNo
amount_usdNo
trajectoryNo
counterpartyNo
irreversibleNo
action_historyNo
evidence_countNo
risk_thresholdNo
sensitive_dataNo
previous_actionsNo
unknown_counterpartyNo
previous_trust_receiptsNo

TDQS

A3.5/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

The description explicitly discloses that this is a verification only: 'FREE_PREFLIGHT execution_authority=false and no funds are moved.' It also gives what the call produces (verdict plus Trust Receipt v1.3). This matches the readOnlyHint and idempotentHint annotations, no contradiction. The description adds significant non-obvious behavior - it cannot execute or move funds - that the annotations alone do not say.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is only two sentences and the core purpose is front-loaded in the first phrase. It wastes nearly nothing. The phrase 'FREE_PREFLIGHT execution_authority=false' is somewhat jargony but adds precise, high-value safety context in a compact way.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness2/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a 16-parameter tool with almost no schema-level descriptions and no output schema, the description is too sparse. It tells the agent why and when to invoke the tool, but not how to properly construct a request against the richer optional context (e.g., trajectory, action_history, previous_trust_receipts). It is not complete enough for an agent to know what inputs matter for a high-quality trust verdict.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters2/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The schema has 16 parameters, yet only the 'action' parameter has a description, and that just says 'AI-native action vocabulary.' The tool description does not try to compensate: it never explains evidence, the trajectory, action_history, amount_usd, counterparty, risk_threshold, sensitive_data, or how these combine into a verification request. For a 6% schema coverage, the description leaves essential parameter meaning to the agent's inference.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description opens with 'VERIFY BEFORE ACT' and immediately scopes the tool to payments, purchases, delegation, approvals, writes, releases, commits, and other consequential actions. It also states the exact return vocabulary (ALLOW, VERIFY, REQUIRE_VERIFICATION, DENY) and that it returns a Trust Receipt, so an agent knows what this tool produces. It does not explicitly distinguish it from the sibling tool, but the main resource and mode are clear.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description gives a clear use case: run this before consequential actions, and it emphasizes 'VERIFY BEFORE ACT'. This is close to an explicit usage rule. However, it never says when NOT to use it or points to an alternative like the sibling tool, leaving the agent without a concrete exclusion or routing decision.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

TDQS

A3.8/5.0
Disambiguation5/5

The two tools have clearly distinct responsibilities: one fetches requirements, the other performs the trust decision. No overlap or ambiguity exists between them.

Naming Consistency4/5

The 'get_' prefix is a recognizable convention, while 'trust_action' is less pattern-consistent. However, with only two tools, the naming is still readable and functional.

Tool Count3/5

Two tools is on the thin side but arguably appropriate for a focused trust-layer purpose. Each tool is value-relevant, yet the surface is minimal.

Completeness4/5

The pair covers core trust evaluation and evidence retrieval, with no clear dead ends. Some post-decision management tools could be missing, but the main autonomous-payment call path is complete.

Resources