Skip to main content
Glama

list_software_anomalies

Read-only

List software anomalies

The software-fingerprinting anomaly feed (spec §6): version downgrades and vendor swaps, both graded notice. A market carve-out — the general /v1/anomalies feed (network) excludes these detectors. Same shape as that feed.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
hostNoFilter to anomalies targeting one host.
seatNoFilter to anomalies targeting one seat.
gradeNoFilter by grade.
limitNoPage size, clamped to [1, 200]. Defaults to 50.
sinceNoOnly include items at or after this ISO 8601 instant.
cursorNoOpaque pagination cursor returned as `next_cursor` by the previous page.
detectorNoFilter by detector (a software detector; others yield an empty page).
acknowledgedNoFilter by acknowledgement state.

TDQS

A4.2/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

The readOnlyHint annotation already declares the tool is a safe read, so the description only needs to add context. It satisfies this by explaining which detectors are included, that both are graded 'notice', and that the output 'has the same shape as the general /v1/anomalies feed'. It reveals encoding/scoping behavior beyond the schema without contradicting the annotation.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is compact: one summary sentence, one scoping sentence with spec reference, and one sentence clarifying carve-out and feed shape. Every sentence earns its place, useful information is front-loaded, and there is no filler.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a read-only list tool with no required parameters and 100% schema coverage, this description is nearly complete. It also covers output shape by pointing to the general feed and the knowledge gap about which detectors/feed are relevant. It leaves some interpretation of 'market carve-out' in jargon, and relies on the reader knowing the general feed's response shape, but these are minor in practice.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The input schema already documents all 8 parameters with 100% coverage, so the description is not required to add parameter-level detail. It does add limited context, such as 'both graded notice' informing expectations around the grade filter, but it does not meaningfully enrich the schema beyond that. Baseline 3 is appropriate while the structured schema carries the load.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description opens with a clear verb and resource: 'List software anomalies', then narrows the scope precisely to the software-fingerprinting anomaly feed: version downgrades and vendor swaps. It distinguishes itself from sibling list_anomalies by explaining this is a market carve-out for detectors the general network-anomaly feed excludes.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It clearly tells the agent when this tool is the right one: software-specific anomalies from the fingerprinting feed. It also explains that the general /v1/anomalies feed is for network anomalies and excludes these detectors, which effectively gives a when-not-to-use signal. It could be stronger by naming list_anomalies as the alternative explicitly, but the carve-out language is sufficient guidance.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

TDQS

A3.8/5.0
Disambiguation4/5

Most tools are cleanly separated by resource type: participants, access points, hosts, providers, incidents, anomalies, and SLA each have their own get/list vocabulary. The main ambiguous pairs are get_provider_sla vs get_provider_sla_by_key, list_providers vs list_public_providers, and get_summary vs get_network_summary.

Naming Consistency4/5

The overall get_/list_ verb_noun pattern is consistent and readable, and plural/singular resource names are mostly clear. There are a few exceptions: get_provider_sla and get_country_providers return collections despite using get_, and list_provider_certs is more of an aggregate posture endpoint than a simple list.

Tool Count2/5

43 tools is well beyond the typical well-scoped MCP surface and will make the tool set harder for an agent to navigate defensibly. The tools are systematically grouped, but this looks like a broad REST API surface rather than a compact, purpose-fit MCP server.

Completeness5/5

For a read-only monitoring and directory domain, the coverage is unusually complete: list/detail endpoints, histories, SLA tables, churn breakdowns, anomalies, incidents, adoption aggregates, software landscape, and quality checks are all represented. The drill-down routes such as churn totals to churn participants also avoid dead ends.

Resources