Skip to main content
Glama

RegSentry Website Tracking Inspector

Server Details

Inspect a public site's tracking signals, grade consent evidence, and get remediation playbooks.

Ownership verified
Status
Healthy
Uptime
100.0% over 21 days
Last Tested
Transport
Streamable HTTP · MCP 2025-11-25
URL

TDQS

A4.2/5.0

Scored across 3 tools

Disambiguation5/5

Each tool has a clearly distinct role: inspect_site_tracking performs an active fetch and reports signals, interpret_consent_evidence analyzes supplied observations, and get_remediation_playbook retrieves guidance. No overlap in purpose.

Naming Consistency5/5

All names use snake_case with a verb_noun pattern (get_, inspect_, interpret_), which is consistent and predictable.

Tool Count5/5

Three tools is at the lower bound of the typical 3-15 range but is well-scoped for a focused inspector, with each tool covering a core operation.

Completeness4/5

The surface covers inspection, interpretation, and remediation guidance, but lacks a tool to list available trackers/playbooks or to capture runtime tracker requests, which could be a minor gap for some workflows.

Available Tools

3 tools
get_remediation_playbookGet tracker remediation playbookA
Read-onlyIdempotent
Inspect

Returns deterministic, tracker-specific consent-gating guidance from RegSentry's maintained playbooks. It does not change a website, contact a vendor, or verify that a fix was implemented.

ParametersJSON Schema
NameRequiredDescriptionDefault
trackerYes

Output Schema

ParametersJSON Schema
NameRequiredDescription
riskYes
stepsYes
docsUrlNo
snippetNo
trackerYes
loadedViaYes
disclaimerYes

TDQS

A4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already provide readOnlyHint=true, idempotentHint=true, and destructiveHint=false, and the description is fully consistent with them. It adds value beyond the annotations by disclosing that the output is 'deterministic' and sourced from 'maintained playbooks,' and by explicitly stating that it does not verify live fixes — meaning the result reflects static guidance rather than current site state. No contradiction.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two sentences totaling roughly 30 words: the first states the core behavior and the second states scope exclusions. Nothing is redundant with the annotations or schema, and the most decision-relevant information is front-loaded.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a single-parameter lookup tool, the description covers purpose, determinism, data source, and non-effects, and the presence of an output schema relieves it of explaining return structure. The clear gaps are the semantics of the 'tracker' parameter (0% schema coverage) and the absence of explicit guidance for choosing between this tool and its siblings. It is adequate but not complete.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters2/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 0%, so the 'tracker' property carries only type, regex pattern, and length bounds with no semantic description. The tool description contributes only the word 'tracker-specific,' implying the parameter identifies a tracker, but never states whether that should be a domain, vendor name, ID, or URL, and gives no examples. With coverage at 0%, the description was expected to compensate and largely does not.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description names a specific verb ('Returns') and a specific resource ('deterministic, tracker-specific consent-gating guidance from RegSentry's maintained playbooks'). The negative scope statements ('does not change a website, contact a vendor, or verify that a fix was implemented') distinguish it from what an action-oriented remediation tool would do, so an agent can tell it apart from siblings like inspect_site_tracking and interpret_consent_evidence. This is a specific, non-tautological purpose statement.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The second sentence gives explicit exclusionary guidance: this tool performs a pure lookup and will not modify a website, contact a vendor, or verify implementation, so an agent knows not to select it for execution or verification tasks. However, it does not explicitly name sibling tools as alternatives for those cases, so routing is bounded but not fully directive.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

inspect_site_trackingInspect site tracking setupA
Read-onlyIdempotent
Inspect

Performs a bounded, non-persisting GET of an authorized public domain's homepage and reports tracker markup, consent setup signals, and runtime-verification gaps. It does not run JavaScript, submit forms, create a RegSentry record, or make a legal determination.

ParametersJSON Schema
NameRequiredDescriptionDefault
domainYesPublic domain only, such as example.com. Do not include a path or query.
authorizationAcknowledgedYesMust be true to confirm the user owns or is authorized to inspect this domain.

Output Schema

ParametersJSON Schema
NameRequiredDescription
scopeYes
domainYes
trackersYes
disclaimerYes
httpStatusYes
limitationsYes
finalHostnameYes
consentSignalsYes
dynamicLoadersYes
consentManagersYes
consentSetupStateYes
runtimeVerificationRequiredYes
trackersRequiringRuntimeVerificationYes

TDQS

A4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already cover the safety profile (readOnlyHint=true, destructiveHint=false, idempotentHint=true), so the bar is lower. The description adds genuinely non-redundant behavior: it does NOT run JavaScript, submit forms, create a RegSentry record, or make legal determinations, and it explicitly notes 'runtime-verification gaps' — meaningful caveats about what the fetch will and won't reveal.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two tight sentences: the first states what it does, the second lists what it deliberately does not do. Front-loaded with the positive capability, no redundant text.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Complete enough for a 2-param, read-only fetch tool with an output schema present (return values need not be described). The negative-capability list closes the biggest behavioral gaps. The only missing element is explicit routing relative to sibling tools.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the schema already documents both parameters including the authorization const and domain format. The description adds only the 'authorized public domain' framing, which is marginal beyond the schema. Baseline 3 is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource ('bounded, non-persisting GET of an authorized public domain's homepage') and enumerates exactly what is reported (tracker markup, consent setup signals, runtime-verification gaps). An agent can distinguish this from the sibling tools, which are about remediation and consent-evidence interpretation rather than direct fetching.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description implies scope via the authorization requirement and the negative list, but it never explicitly says when to use this tool versus interpret_consent_evidence or get_remediation_playbook. No explicit when-to-use or when-not-to-use routing is provided.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections.

  1. 1 tool update
    • Changedinspect_site_tracking3 fields changed
      • addedOutput schema / properties / trackers / items / description
        Added value: +"A static HTML tracker reference; runtime firing and violations are not established."
      • removedOutput schema / properties / trackers / items / properties / violating
        Removed value: -{
        -  "type": "boolean"
        -}
      • changedOutput schema / properties / trackers / items / required
        Previous value: -[
        -  "name",
        -  "category",
        -  "violating"
        -]New value: +[
        +  "name",
        +  "category"
        +]
  2. 3 tool updates
    • First observedget_remediation_playbook
    • First observedinspect_site_tracking
    • First observedinterpret_consent_evidence

Publisher details

Operator
Soxoa LLC
Operator website
https://soxoa.com
Vendor relationship
First-party
Restrictions
Unknown

Related MCP Connectors

Related MCP Servers

  • A
    license
    A
    quality
    D
    maintenance
    Audit any website for privacy, security, accessibility, and performance issues — with scores, grades, and actionable fix instructions. No account required.
    3
    14 npm
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Read-only observation of a single live URL: parses static HTML to report security posture, forms, links, accessibility signals, and leaks, with described fixes. SSRF-gated and safe, never executes JavaScript.
    92 npm
    MIT
  • F
    license
    Not graded
    quality
    B
    maintenance
    Passive website security and trust auditor that checks for security, SEO, AI surface, email, and other exposures, producing a score and remediation plan.
    -
Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources