Skip to main content
Glama

Robot Actions — Remote Device Control

ios_traffic_flows

Snapshot recent DECRYPTED HTTPS flows (request/response) captured since ios_traffic_start. Each flow: method, url, host, status, contentType, req/resp sizes, durationMs. Set includeBodies to also return headers + (truncated) request/response bodies. Filter by urlSubstring or onlyErrors. Returns the most recent limit flows.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
udidYesiOS device UDID
limitNoMax flows to return, most recent first-matched (default 100)
onlyErrorsNoOnly 5xx / connection-error flows
urlSubstringNoOnly flows whose URL contains this substring
includeBodiesNoInclude headers + bodies (each body capped at 32000 chars). Default false.

TDQS

A4.4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations provided, the description carries the full burden of behavioral disclosure. It goes beyond the schema by mentioning that only DECRYPTED HTTPS flows are captured, that bodies are truncated, and that the snapshot is since ios_traffic_start. These are meaningful operational traits. It does not explicitly mention that the capture must be active, but this is strongly implied by the phrasing and the companion start tool.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Three sentences, tightly packed with relevant information. The first sentence states the core purpose and return fields. The second explains the optional body inclusion. The third covers filtering and limit. No filler or redundant phrasing; every sentence earns its place.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given that there is no output schema, the description does well to list the returned fields and optional body payload. It covers the main options and their effects. The primary gap is not explicitly stating that a capture must be in progress (started via ios_traffic_start), but the phrase 'since ios_traffic_start' covers this context for an informed agent. Overall, it is sufficient for a tool with this level of complexity.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the baseline is 3. The description adds value by explaining what includeBodies returns (headers + truncated bodies), how urlSubstring and onlyErrors filter flows, and what fields each flow contains (method, url, host, status, etc.). It connects the 'limit' parameter to the 'most recent' behavior, reinforcing rather than duplicating the schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a specific action ('Snapshot recent DECRYPTED HTTPS flows') with a clear resource and scoping. It lists the fields returned, distinguishing it from starting/stopping traffic capture (ios_traffic_start/stop) and from Android equivalents. The verb 'snapshot' and the explicit 'since ios_traffic_start' establish a unique purpose without ambiguity.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description implies when to use the tool: after ios_traffic_start has been called. It gives practical guidance on how to use includeBodies, urlSubstring, onlyErrors, and limit. It stops short of explicitly naming alternatives or excluding cases (e.g., 'use android_traffic_flows for Android'), but the sibling context and platform prefix make the usage clear.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

TDQS

B3.1/5.0
Disambiguation2/5

The set contains near-identical duplicate families: web_* and playwright_* expose ~15 pairs of the same desktop-grid-browser operations (web_get_text/playwright_get_text, web_reload/playwright_reload), and screenshot/log/network/mock capabilities each have 5-8 entry points (device_screenshot vs android_mjpeg_screenshot vs ios_screenshot vs ios_fast_screenshot vs web_screenshot vs webpage_screenshot vs session_screenshot). Many individual descriptions carefully draw boundaries (devtools vs traffic, HID vs session), but an agent cannot reliably distinguish web_* from playwright_*, and ios_screenshot/ios_fast_screenshot/ios_mjpeg_screenshot blur together.

Naming Consistency2/5

The prefix scheme is broken: Android functionality is split arbitrarily between android_* and device_* (device_screenshot vs android_mjpeg_screenshot), the desktop browser gets two parallel prefixes (web_* and playwright_*), and verbs vary across equivalents (device_navigate_url vs web_navigate vs ios_safari_navigate). session_* uses bare verbs (session_url, session_back), and the same concept gets different names (ios_clipboard_get_hid vs ios_get_pasteboard; device_screen vs ios_orientation).

Tool Count1/5

333 tools is an extreme count by any measure — far beyond the 50+ threshold — and much of the bulk is duplicative (the web_*/playwright_* pairs alone double ~15 slots) or out-of-scope for a device-control server (TestRail, Jira, AzDO, agent memory, secret variables, feedback). Even granting that remote device control + test automation is a broad domain, this surface will devastate agent context budgets and is impossible to navigate coherently.

Completeness4/5

The core device-control and test-automation domain is remarkably thorough: Android and iOS each have full interaction, app-lifecycle, file, network/proxy, performance, crash, accessibility, recording, and replay coverage, with CRUD lifecycles for flows, suites, app uploads, TestRail cases, and visual-review baselines. Minor gaps exist at the margins — Jira/AzDO lack update/transition/comment operations, and iOS cannot open/close tabs — but the central workflows have no dead ends.

Resources