Skip to main content
Glama

Security audit

audit_security

Audit the website with every security module included in the connected account by default. A default Free audit on an unverified site runs its public security checks and explains the additional checks unlocked by ownership verification. Explicit protected selections require verification. Explicit profile, module and port selections are supported within the account entitlement. Returns all observed findings and identifies unavailable measurements or engines. Provide target to start an audit, or jobId to poll a running one. Long audits may return status: running with a jobId. Wait retryAfterMs, then call the same tool using the returned pollArguments, including target and jobId, until it returns the final result. Copy pollArguments unchanged; do not add scan options. Clients that support jobId alone may also use it. Polling retrieves the same audit without starting another scan or reserving more quota. Do not present running as completed and do not start a replacement audit while it is running.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
langNoReport language (default en): en, tr, es, de, fr, pt, it, ja, zh.
jobIdNoResume an existing audit by polling this same tool with the returned pollArguments. Keep target and jobId unchanged. If repeating scan options, supply every original argument unchanged. Never invent a jobId.
portsNoOptional port selection: top, common, all, or comma-separated ports/ranges. Account limits apply; default top.
targetNoTarget website URL or domain you own / are authorized to audit (e.g. https://example.com).
modulesNoOptional explicit security module selection. Omit to use the plan scope. Protected checks require current target ownership; unavailable engines are reported as unmeasured.
profileNoOptional security profile included in the account. Omit to run all security modules included in the connected plan.

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault

No arguments

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed1 schema field changed
    • removedInput schema / anyOf
      Removed value: -[
      -  {
      -    "required": [
      -      "target"
      -    ]
      -  },
      -  {
      -    "required": [
      -      "jobId"
      -    ]
      -  }
      -]
  2. Changed3 schema fields changed
    • changedInput schema / anyOf
      Previous value: -[
      -  {
      -    "required": [
      -      "target"
      -    ]
      -  },
      -  {
      -    "maxProperties": 1,
      -    "required": [
      -      "jobId"
      -    ]
      -  }
      -]New value: +[
      +  {
      +    "required": [
      +      "target"
      +    ]
      +  },
      +  {
      +    "required": [
      +      "jobId"
      +    ]
      +  }
      +]
    • changedInput schema / properties / jobId / description
      Previous value: -"Resume an existing audit by polling this same tool with its returned jobId. Prefer jobId alone; if repeating other arguments, supply every original argument unchanged. Never invent a jobId."New value: +"Resume an existing audit by polling this same tool with the returned pollArguments. Keep target and jobId unchanged. If repeating scan options, supply every original argument unchanged. Never invent a jobId."
    • changedOutput schema / oneOf
      Previous value: -[
      -  {
      -    "oneOf": [
      -      {
      -        "additionalProperties": true,
      -        "properties": {
      -          "auditDetails": {
      -            "additionalProperties": true,
      -            "description": "Complete available scope, check states and measurement evidence; unmeasured checks are not passes.",
      -            "type": "object"
      -          },
      -          "counts": {
      -            "additionalProperties": false,
      -            "description": "Finding totals grouped by normalized severity.",
      -            "properties": {
      -              "critical": {
      -                "description": "Number of critical findings.",
      -                "minimum": 0,
      -                "type": "integer"
      -              },
      -              "high": {
      -                "description": "Number of high-severity findings.",
      -                "minimum": 0,
      -                "type": "integer"
      -              },
      -              "info": {
      -                "description": "Number of informational findings.",
      -                "minimum": 0,
      -                "type": "integer"
      -              },
      -              "low": {
      -                "description": "Number of low-severity findings.",
      -                "minimum": 0,
      -                "type": "integer"
      -              },
      -              "medium": {
      -                "description": "Number of medium-severity findings.",
      -                "minimum": 0,
      -                "type": "integer"
      -              }
      -            },
      -            "required": [
      -              "critical",
      -              "high",
      -              "medium",
      -              "low",
      -              "info"
      -            ],
      -            "type": "object"
      -          },
      -          "coverageStatus": {
      -            "description": "Availability of measurements within the requested methods and account scope; not a claim to test every possible website behavior.",
      -            "enum": [
      -              "measured",
      -              "partial",
      -              "unavailable",
      -              "not_applicable"
      -            ],
      -            "type": "string"
      -          },
      -          "executionComplete": {
      -            "description": "Whether all requested pillar runners returned. This is separate from measurement coverage.",
      -            "type": "boolean"
      -          },
      -          "findings": {
      -            "description": "Prioritized findings with evidence, impact, and remediation.",
      -            "items": {
      -              "additionalProperties": false,
      -              "properties": {
      -                "category": {
      -                  "description": "Stable audit category for grouping related findings.",
      -                  "type": "string"
      -                },
      -                "evidence": {
      -                  "description": "Bounded observation that supports the finding.",
      -                  "type": "string"
      -                },
      -                "findingKey": {
      -                  "description": "Deterministic pillar-scoped identity for before/after comparison.",
      -                  "maxLength": 512,
      -                  "minLength": 1,
      -                  "type": "string"
      -                },
      -                "impact": {
      -                  "description": "Why the finding matters to the audited website.",
      -                  "type": "string"
      -                },
      -                "location": {
      -                  "description": "Observed URL or path with credentials and query secrets removed, when available.",
      -                  "type": "string"
      -                },
      -                "remediation": {
      -                  "description": "Concrete recommended fix or mitigation.",
      -                  "type": "string"
      -                },
      -                "severity": {
      -                  "description": "Normalized finding severity: critical, high, medium, low, or info.",
      -                  "type": "string"
      -                },
      -                "title": {
      -                  "description": "Short human-readable finding title.",
      -                  "type": "string"
      -                }
      -              },
      -              "required": [
      -                "findingKey",
      -                "severity",
      -                "title",
      -                "evidence",
      -                "impact",
      -                "remediation",
      -                "category"
      -              ],
      -              "type": "object"
      -            },
      -            "type": "array"
      -          },
      -          "findingsTruncated": {
      -            "description": "True when additional findings exist outside this response.",
      -            "type": "boolean"
      -          },
      -          "grade": {
      -            "description": "Human-readable grade, or null when unavailable.",
      -            "type": [
      -              "string",
      -              "null"
      -            ]
      -          },
      -          "kind": {
      -            "description": "Audit pillar represented by this result.",
      -            "type": "string"
      -          },
      -          "passingChecks": {
      -            "description": "Number of checks that passed or reported protection.",
      -            "minimum": 0,
      -            "type": "integer"
      -          },
      -          "passingFindings": {
      -            "description": "Positive observations retained with their complete evidence.",
      -            "items": {
      -              "additionalProperties": false,
      -              "properties": {
      -                "category": {
      -                  "description": "Stable audit category for grouping related findings.",
      -                  "type": "string"
      -                },
      -                "evidence": {
      -                  "description": "Bounded observation that supports the finding.",
      -                  "type": "string"
      -                },
      -                "findingKey": {
      -                  "description": "Deterministic pillar-scoped identity for before/after comparison.",
      -                  "maxLength": 512,
      -                  "minLength": 1,
      -                  "type": "string"
      -                },
      -                "impact": {
      -                  "description": "Why the finding matters to the audited website.",
      -                  "type": "string"
      -                },
      -                "location": {
      -                  "description": "Observed URL or path with credentials and query secrets removed, when available.",
      -                  "type": "string"
      -                },
      -                "remediation": {
      -                  "description": "Concrete recommended fix or mitigation.",
      -                  "type": "string"
      -                },
      -                "severity": {
      -                  "description": "Normalized finding severity: critical, high, medium, low, or info.",
      -                  "type": "string"
      -                },
      -                "title": {
      -                  "description": "Short human-readable finding title.",
      -                  "type": "string"
      -                }
      -              },
      -              "required": [
      -                "findingKey",
      -                "severity",
      -                "title",
      -                "evidence",
      -                "impact",
      -                "remediation",
      -                "category"
      -              ],
      -              "type": "object"
      -            },
      -            "type": "array"
      -          },
      -          "returnedFindings": {
      -            "description": "Number of findings included in this response.",
      -            "minimum": 0,
      -            "type": "integer"
      -          },
      -          "score": {
      -            "description": "Measured score from 0 to 100, or null when unavailable.",
      -            "type": [
      -              "number",
      -              "null"
      -            ]
      -          },
      -          "status": {
      -            "description": "Completed when requested measurements are available; partial when a requested runner or measurement is unavailable.",
      -            "enum": [
      -              "completed",
      -              "partial"
      -            ],
      -            "type": "string"
      -          },
      -          "target": {
      -            "description": "Canonical audited target.",
      -            "type": "string"
      -          },
      -          "total": {
      -            "description": "Total findings produced before response truncation.",
      -            "minimum": 0,
      -            "type": "integer"
      -          }
      -        },
      -        "required": [
      -          "target",
      -          "kind",
      -          "score",
      -          "grade",
      -          "counts",
      -          "total",
      -          "returnedFindings",
      -          "findingsTruncated",
      -          "passingChecks",
      -          "findings"
      -        ],
      -        "type": "object"
      -      },
      -      {
      -        "additionalProperties": false,
      -        "properties": {
      -          "executionComplete": {
      -            "const": false,
      -            "description": "False until the entire audit result is ready for delivery.",
      -            "type": "boolean"
      -          },
      -          "jobId": {
      -            "description": "Opaque temporary job identifier bound to this account, tool and MCP surface.",
      -            "pattern": "^mj_[A-Za-z0-9_-]{32}$",
      -            "type": "string"
      -          },
      -          "nextAction": {
      -            "const": "poll_same_tool",
      -            "description": "Call this same tool again with pollArguments.",
      -            "type": "string"
      -          },
      -          "pollArguments": {
      -            "additionalProperties": false,
      -            "description": "Arguments for retrieving this existing audit without starting another scan.",
      -            "properties": {
      -              "jobId": {
      -                "description": "The same opaque audit job identifier.",
      -                "pattern": "^mj_[A-Za-z0-9_-]{32}$",
      -                "type": "string"
      -              }
      -            },
      -            "required": [
      -              "jobId"
      -            ],
      -            "type": "object"
      -          },
      -          "retryAfterMs": {
      -            "description": "Suggested delay in milliseconds before polling this job again.",
      -            "minimum": 0,
      -            "type": "integer"
      -          },
      -          "status": {
      -            "const": "running",
      -            "description": "The audit is still executing or completing durable delivery.",
      -            "type": "string"
      -          }
      -        },
      -        "required": [
      -          "status",
      -          "jobId",
      -          "executionComplete",
      -          "nextAction",
      -          "pollArguments",
      -          "retryAfterMs"
      -        ],
      -        "type": "object"
      -      },
      -      {
      -        "additionalProperties": false,
      -        "properties": {
      -          "auditExecuted": {
      -            "const": false,
      -            "description": "This request did not execute a new audit.",
      -            "type": "boolean"
      -          },
      -          "reason": {
      -            "description": "The recoverable job request prerequisite.",
      -            "enum": [
      -              "audit_job_busy",
      -              "audit_job_unavailable",
      -              "audit_job_argument_mismatch",
      -              "audit_job_invalid_arguments"
      -            ],
      -            "type": "string"
      -          },
      -          "status": {
      -            "const": "action_required",
      -            "description": "This request did not start a new audit.",
      -            "type": "string"
      -          },
      -          "usageConsumed": {
      -            "const": false,
      -            "description": "This request did not consume additional audit allowance.",
      -            "type": "boolean"
      -          }
      -        },
      -        "required": [
      -          "status",
      -          "reason",
      -          "auditExecuted",
      -          "usageConsumed"
      -        ],
      -        "type": "object"
      -      }
      -    ],
      -    "type": "object"
      -  },
      -  {
      -    "additionalProperties": false,
      -    "properties": {
      -      "auditExecuted": {
      -        "const": false,
      -        "type": "boolean"
      -      },
      -      "reason": {
      -        "enum": [
      -          "entitlement_required",
      -          "target_verification_required",
      -          "target_reverification_required",
      -          "verification_scope_required",
      -          "usage_limit_reached",
      -          "authorization_consent_required"
      -        ],
      -        "type": "string"
      -      },
      -      "status": {
      -        "const": "action_required",
      -        "type": "string"
      -      },
      -      "usageConsumed": {
      -        "const": false,
      -        "type": "boolean"
      -      }
      -    },
      -    "required": [
      -      "status",
      -      "reason",
      -      "auditExecuted",
      -      "usageConsumed"
      -    ],
      -    "type": "object"
      -  }
      -]New value: +[
      +  {
      +    "oneOf": [
      +      {
      +        "additionalProperties": true,
      +        "properties": {
      +          "auditDetails": {
      +            "additionalProperties": true,
      +            "description": "Complete available scope, check states and measurement evidence; unmeasured checks are not passes.",
      +            "type": "object"
      +          },
      +          "counts": {
      +            "additionalProperties": false,
      +            "description": "Finding totals grouped by normalized severity.",
      +            "properties": {
      +              "critical": {
      +                "description": "Number of critical findings.",
      +                "minimum": 0,
      +                "type": "integer"
      +              },
      +              "high": {
      +                "description": "Number of high-severity findings.",
      +                "minimum": 0,
      +                "type": "integer"
      +              },
      +              "info": {
      +                "description": "Number of informational findings.",
      +                "minimum": 0,
      +                "type": "integer"
      +              },
      +              "low": {
      +                "description": "Number of low-severity findings.",
      +                "minimum": 0,
      +                "type": "integer"
      +              },
      +              "medium": {
      +                "description": "Number of medium-severity findings.",
      +                "minimum": 0,
      +                "type": "integer"
      +              }
      +            },
      +            "required": [
      +              "critical",
      +              "high",
      +              "medium",
      +              "low",
      +              "info"
      +            ],
      +            "type": "object"
      +          },
      +          "coverageStatus": {
      +            "description": "Availability of measurements within the requested methods and account scope; not a claim to test every possible website behavior.",
      +            "enum": [
      +              "measured",
      +              "partial",
      +              "unavailable",
      +              "not_applicable"
      +            ],
      +            "type": "string"
      +          },
      +          "executionComplete": {
      +            "description": "Whether all requested pillar runners returned. This is separate from measurement coverage.",
      +            "type": "boolean"
      +          },
      +          "findings": {
      +            "description": "Prioritized findings with evidence, impact, and remediation.",
      +            "items": {
      +              "additionalProperties": false,
      +              "properties": {
      +                "category": {
      +                  "description": "Stable audit category for grouping related findings.",
      +                  "type": "string"
      +                },
      +                "evidence": {
      +                  "description": "Bounded observation that supports the finding.",
      +                  "type": "string"
      +                },
      +                "findingKey": {
      +                  "description": "Deterministic pillar-scoped identity for before/after comparison.",
      +                  "maxLength": 512,
      +                  "minLength": 1,
      +                  "type": "string"
      +                },
      +                "impact": {
      +                  "description": "Why the finding matters to the audited website.",
      +                  "type": "string"
      +                },
      +                "location": {
      +                  "description": "Observed URL or path with credentials and query secrets removed, when available.",
      +                  "type": "string"
      +                },
      +                "remediation": {
      +                  "description": "Concrete recommended fix or mitigation.",
      +                  "type": "string"
      +                },
      +                "severity": {
      +                  "description": "Normalized finding severity: critical, high, medium, low, or info.",
      +                  "type": "string"
      +                },
      +                "title": {
      +                  "description": "Short human-readable finding title.",
      +                  "type": "string"
      +                }
      +              },
      +              "required": [
      +                "findingKey",
      +                "severity",
      +                "title",
      +                "evidence",
      +                "impact",
      +                "remediation",
      +                "category"
      +              ],
      +              "type": "object"
      +            },
      +            "type": "array"
      +          },
      +          "findingsTruncated": {
      +            "description": "True when additional findings exist outside this response.",
      +            "type": "boolean"
      +          },
      +          "grade": {
      +            "description": "Human-readable grade, or null when unavailable.",
      +            "type": [
      +              "string",
      +              "null"
      +            ]
      +          },
      +          "kind": {
      +            "description": "Audit pillar represented by this result.",
      +            "type": "string"
      +          },
      +          "passingChecks": {
      +            "description": "Number of checks that passed or reported protection.",
      +            "minimum": 0,
      +            "type": "integer"
      +          },
      +          "passingFindings": {
      +            "description": "Positive observations retained with their complete evidence.",
      +            "items": {
      +              "additionalProperties": false,
      +              "properties": {
      +                "category": {
      +                  "description": "Stable audit category for grouping related findings.",
      +                  "type": "string"
      +                },
      +                "evidence": {
      +                  "description": "Bounded observation that supports the finding.",
      +                  "type": "string"
      +                },
      +                "findingKey": {
      +                  "description": "Deterministic pillar-scoped identity for before/after comparison.",
      +                  "maxLength": 512,
      +                  "minLength": 1,
      +                  "type": "string"
      +                },
      +                "impact": {
      +                  "description": "Why the finding matters to the audited website.",
      +                  "type": "string"
      +                },
      +                "location": {
      +                  "description": "Observed URL or path with credentials and query secrets removed, when available.",
      +                  "type": "string"
      +                },
      +                "remediation": {
      +                  "description": "Concrete recommended fix or mitigation.",
      +                  "type": "string"
      +                },
      +                "severity": {
      +                  "description": "Normalized finding severity: critical, high, medium, low, or info.",
      +                  "type": "string"
      +                },
      +                "title": {
      +                  "description": "Short human-readable finding title.",
      +                  "type": "string"
      +                }
      +              },
      +              "required": [
      +                "findingKey",
      +                "severity",
      +                "title",
      +                "evidence",
      +                "impact",
      +                "remediation",
      +                "category"
      +              ],
      +              "type": "object"
      +            },
      +            "type": "array"
      +          },
      +          "returnedFindings": {
      +            "description": "Number of findings included in this response.",
      +            "minimum": 0,
      +            "type": "integer"
      +          },
      +          "score": {
      +            "description": "Measured score from 0 to 100, or null when unavailable.",
      +            "type": [
      +              "number",
      +              "null"
      +            ]
      +          },
      +          "status": {
      +            "description": "Completed when requested measurements are available; partial when a requested runner or measurement is unavailable.",
      +            "enum": [
      +              "completed",
      +              "partial"
      +            ],
      +            "type": "string"
      +          },
      +          "target": {
      +            "description": "Canonical audited target.",
      +            "type": "string"
      +          },
      +          "total": {
      +            "description": "Total findings produced before response truncation.",
      +            "minimum": 0,
      +            "type": "integer"
      +          }
      +        },
      +        "required": [
      +          "target",
      +          "kind",
      +          "score",
      +          "grade",
      +          "counts",
      +          "total",
      +          "returnedFindings",
      +          "findingsTruncated",
      +          "passingChecks",
      +          "findings"
      +        ],
      +        "type": "object"
      +      },
      +      {
      +        "additionalProperties": false,
      +        "properties": {
      +          "executionComplete": {
      +            "const": false,
      +            "description": "False until the entire audit result is ready for delivery.",
      +            "type": "boolean"
      +          },
      +          "jobId": {
      +            "description": "Opaque temporary job identifier bound to this account, tool and MCP surface.",
      +            "pattern": "^mj_[A-Za-z0-9_-]{32}$",
      +            "type": "string"
      +          },
      +          "nextAction": {
      +            "const": "poll_same_tool",
      +            "description": "Call this same tool again with pollArguments.",
      +            "type": "string"
      +          },
      +          "pollArguments": {
      +            "additionalProperties": false,
      +            "description": "Copy these arguments unchanged to retrieve this existing audit without starting another scan. The public target supports clients that require a target on every call.",
      +            "properties": {
      +              "jobId": {
      +                "description": "The same opaque audit job identifier.",
      +                "pattern": "^mj_[A-Za-z0-9_-]{32}$",
      +                "type": "string"
      +              },
      +              "target": {
      +                "description": "Public polling target for this job, without URL credentials, query or fragment. It does not change the original scan target.",
      +                "maxLength": 2048,
      +                "type": "string"
      +              }
      +            },
      +            "required": [
      +              "jobId"
      +            ],
      +            "type": "object"
      +          },
      +          "retryAfterMs": {
      +            "description": "Suggested delay in milliseconds before polling this job again.",
      +            "minimum": 0,
      +            "type": "integer"
      +          },
      +          "status": {
      +            "const": "running",
      +            "description": "The audit is still executing or completing durable delivery.",
      +            "type": "string"
      +          }
      +        },
      +        "required": [
      +          "status",
      +          "jobId",
      +          "executionComplete",
      +          "nextAction",
      +          "pollArguments",
      +          "retryAfterMs"
      +        ],
      +        "type": "object"
      +      },
      +      {
      +        "additionalProperties": false,
      +        "properties": {
      +          "auditExecuted": {
      +            "const": false,
      +            "description": "This request did not execute a new audit.",
      +            "type": "boolean"
      +          },
      +          "reason": {
      +            "description": "The recoverable job request prerequisite.",
      +            "enum": [
      +              "audit_job_busy",
      +              "audit_job_unavailable",
      +              "audit_job_argument_mismatch",
      +              "audit_job_invalid_arguments"
      +            ],
      +            "type": "string"
      +          },
      +          "status": {
      +            "const": "action_required",
      +            "description": "This request did not start a new audit.",
      +            "type": "string"
      +          },
      +          "usageConsumed": {
      +            "const": false,
      +            "description": "This request did not consume additional audit allowance.",
      +            "type": "boolean"
      +          }
      +        },
      +        "required": [
      +          "status",
      +          "reason",
      +          "auditExecuted",
      +          "usageConsumed"
      +        ],
      +        "type": "object"
      +      }
      +    ],
      +    "type": "object"
      +  },
      +  {
      +    "additionalProperties": false,
      +    "properties": {
      +      "auditExecuted": {
      +        "const": false,
      +        "type": "boolean"
      +      },
      +      "reason": {
      +        "enum": [
      +          "entitlement_required",
      +          "target_verification_required",
      +          "target_reverification_required",
      +          "verification_scope_required",
      +          "usage_limit_reached",
      +          "authorization_consent_required"
      +        ],
      +        "type": "string"
      +      },
      +      "status": {
      +        "const": "action_required",
      +        "type": "string"
      +      },
      +      "usageConsumed": {
      +        "const": false,
      +        "type": "boolean"
      +      }
      +    },
      +    "required": [
      +      "status",
      +      "reason",
      +      "auditExecuted",
      +      "usageConsumed"
      +    ],
      +    "type": "object"
      +  }
      +]
  3. Changed1 schema field changed
    • changedOutput schema / oneOf
      Previous value: -[
      -  {
      -    "additionalProperties": true,
      -    "properties": {
      -      "auditDetails": {
      -        "additionalProperties": true,
      -        "description": "Complete available scope, check states and measurement evidence; unmeasured checks are not passes.",
      -        "type": "object"
      -      },
      -      "counts": {
      -        "additionalProperties": false,
      -        "description": "Finding totals grouped by normalized severity.",
      -        "properties": {
      -          "critical": {
      -            "description": "Number of critical findings.",
      -            "minimum": 0,
      -            "type": "integer"
      -          },
      -          "high": {
      -            "description": "Number of high-severity findings.",
      -            "minimum": 0,
      -            "type": "integer"
      -          },
      -          "info": {
      -            "description": "Number of informational findings.",
      -            "minimum": 0,
      -            "type": "integer"
      -          },
      -          "low": {
      -            "description": "Number of low-severity findings.",
      -            "minimum": 0,
      -            "type": "integer"
      -          },
      -          "medium": {
      -            "description": "Number of medium-severity findings.",
      -            "minimum": 0,
      -            "type": "integer"
      -          }
      -        },
      -        "required": [
      -          "critical",
      -          "high",
      -          "medium",
      -          "low",
      -          "info"
      -        ],
      -        "type": "object"
      -      },
      -      "coverageStatus": {
      -        "description": "Availability of measurements within the requested methods and account scope; not a claim to test every possible website behavior.",
      -        "enum": [
      -          "measured",
      -          "partial",
      -          "unavailable",
      -          "not_applicable"
      -        ],
      -        "type": "string"
      -      },
      -      "executionComplete": {
      -        "description": "Whether all requested pillar runners returned. This is separate from measurement coverage.",
      -        "type": "boolean"
      -      },
      -      "findings": {
      -        "description": "Prioritized findings with evidence, impact, and remediation.",
      -        "items": {
      -          "additionalProperties": false,
      -          "properties": {
      -            "category": {
      -              "description": "Stable audit category for grouping related findings.",
      -              "type": "string"
      -            },
      -            "evidence": {
      -              "description": "Bounded observation that supports the finding.",
      -              "type": "string"
      -            },
      -            "findingKey": {
      -              "description": "Deterministic pillar-scoped identity for before/after comparison.",
      -              "maxLength": 512,
      -              "minLength": 1,
      -              "type": "string"
      -            },
      -            "impact": {
      -              "description": "Why the finding matters to the audited website.",
      -              "type": "string"
      -            },
      -            "location": {
      -              "description": "Observed URL or path with credentials and query secrets removed, when available.",
      -              "type": "string"
      -            },
      -            "remediation": {
      -              "description": "Concrete recommended fix or mitigation.",
      -              "type": "string"
      -            },
      -            "severity": {
      -              "description": "Normalized finding severity: critical, high, medium, low, or info.",
      -              "type": "string"
      -            },
      -            "title": {
      -              "description": "Short human-readable finding title.",
      -              "type": "string"
      -            }
      -          },
      -          "required": [
      -            "findingKey",
      -            "severity",
      -            "title",
      -            "evidence",
      -            "impact",
      -            "remediation",
      -            "category"
      -          ],
      -          "type": "object"
      -        },
      -        "type": "array"
      -      },
      -      "findingsTruncated": {
      -        "description": "True when additional findings exist outside this response.",
      -        "type": "boolean"
      -      },
      -      "grade": {
      -        "description": "Human-readable grade, or null when unavailable.",
      -        "type": [
      -          "string",
      -          "null"
      -        ]
      -      },
      -      "kind": {
      -        "description": "Audit pillar represented by this result.",
      -        "type": "string"
      -      },
      -      "passingChecks": {
      -        "description": "Number of checks that passed or reported protection.",
      -        "minimum": 0,
      -        "type": "integer"
      -      },
      -      "passingFindings": {
      -        "description": "Positive observations retained with their complete evidence.",
      -        "items": {
      -          "additionalProperties": false,
      -          "properties": {
      -            "category": {
      -              "description": "Stable audit category for grouping related findings.",
      -              "type": "string"
      -            },
      -            "evidence": {
      -              "description": "Bounded observation that supports the finding.",
      -              "type": "string"
      -            },
      -            "findingKey": {
      -              "description": "Deterministic pillar-scoped identity for before/after comparison.",
      -              "maxLength": 512,
      -              "minLength": 1,
      -              "type": "string"
      -            },
      -            "impact": {
      -              "description": "Why the finding matters to the audited website.",
      -              "type": "string"
      -            },
      -            "location": {
      -              "description": "Observed URL or path with credentials and query secrets removed, when available.",
      -              "type": "string"
      -            },
      -            "remediation": {
      -              "description": "Concrete recommended fix or mitigation.",
      -              "type": "string"
      -            },
      -            "severity": {
      -              "description": "Normalized finding severity: critical, high, medium, low, or info.",
      -              "type": "string"
      -            },
      -            "title": {
      -              "description": "Short human-readable finding title.",
      -              "type": "string"
      -            }
      -          },
      -          "required": [
      -            "findingKey",
      -            "severity",
      -            "title",
      -            "evidence",
      -            "impact",
      -            "remediation",
      -            "category"
      -          ],
      -          "type": "object"
      -        },
      -        "type": "array"
      -      },
      -      "returnedFindings": {
      -        "description": "Number of findings included in this response.",
      -        "minimum": 0,
      -        "type": "integer"
      -      },
      -      "score": {
      -        "description": "Measured score from 0 to 100, or null when unavailable.",
      -        "type": [
      -          "number",
      -          "null"
      -        ]
      -      },
      -      "status": {
      -        "description": "Completed when requested measurements are available; partial when a requested runner or measurement is unavailable.",
      -        "enum": [
      -          "completed",
      -          "partial"
      -        ],
      -        "type": "string"
      -      },
      -      "target": {
      -        "description": "Canonical audited target.",
      -        "type": "string"
      -      },
      -      "total": {
      -        "description": "Total findings produced before response truncation.",
      -        "minimum": 0,
      -        "type": "integer"
      -      }
      -    },
      -    "required": [
      -      "target",
      -      "kind",
      -      "score",
      -      "grade",
      -      "counts",
      -      "total",
      -      "returnedFindings",
      -      "findingsTruncated",
      -      "passingChecks",
      -      "findings"
      -    ],
      -    "type": "object"
      -  },
      -  {
      -    "additionalProperties": false,
      -    "properties": {
      -      "executionComplete": {
      -        "const": false,
      -        "description": "False until the entire audit result is ready for delivery.",
      -        "type": "boolean"
      -      },
      -      "jobId": {
      -        "description": "Opaque temporary job identifier bound to this account, tool and MCP surface.",
      -        "pattern": "^mj_[A-Za-z0-9_-]{32}$",
      -        "type": "string"
      -      },
      -      "nextAction": {
      -        "const": "poll_same_tool",
      -        "description": "Call this same tool again with pollArguments.",
      -        "type": "string"
      -      },
      -      "pollArguments": {
      -        "additionalProperties": false,
      -        "description": "Arguments for retrieving this existing audit without starting another scan.",
      -        "properties": {
      -          "jobId": {
      -            "description": "The same opaque audit job identifier.",
      -            "pattern": "^mj_[A-Za-z0-9_-]{32}$",
      -            "type": "string"
      -          }
      -        },
      -        "required": [
      -          "jobId"
      -        ],
      -        "type": "object"
      -      },
      -      "retryAfterMs": {
      -        "description": "Suggested delay in milliseconds before polling this job again.",
      -        "minimum": 0,
      -        "type": "integer"
      -      },
      -      "status": {
      -        "const": "running",
      -        "description": "The audit is still executing or completing durable delivery.",
      -        "type": "string"
      -      }
      -    },
      -    "required": [
      -      "status",
      -      "jobId",
      -      "executionComplete",
      -      "nextAction",
      -      "pollArguments",
      -      "retryAfterMs"
      -    ],
      -    "type": "object"
      -  },
      -  {
      -    "additionalProperties": false,
      -    "properties": {
      -      "auditExecuted": {
      -        "const": false,
      -        "description": "This request did not execute a new audit.",
      -        "type": "boolean"
      -      },
      -      "reason": {
      -        "description": "The recoverable job request prerequisite.",
      -        "enum": [
      -          "audit_job_busy",
      -          "audit_job_unavailable",
      -          "audit_job_argument_mismatch",
      -          "audit_job_invalid_arguments"
      -        ],
      -        "type": "string"
      -      },
      -      "status": {
      -        "const": "action_required",
      -        "description": "This request did not start a new audit.",
      -        "type": "string"
      -      },
      -      "usageConsumed": {
      -        "const": false,
      -        "description": "This request did not consume additional audit allowance.",
      -        "type": "boolean"
      -      }
      -    },
      -    "required": [
      -      "status",
      -      "reason",
      -      "auditExecuted",
      -      "usageConsumed"
      -    ],
      -    "type": "object"
      -  }
      -]New value: +[
      +  {
      +    "oneOf": [
      +      {
      +        "additionalProperties": true,
      +        "properties": {
      +          "auditDetails": {
      +            "additionalProperties": true,
      +            "description": "Complete available scope, check states and measurement evidence; unmeasured checks are not passes.",
      +            "type": "object"
      +          },
      +          "counts": {
      +            "additionalProperties": false,
      +            "description": "Finding totals grouped by normalized severity.",
      +            "properties": {
      +              "critical": {
      +                "description": "Number of critical findings.",
      +                "minimum": 0,
      +                "type": "integer"
      +              },
      +              "high": {
      +                "description": "Number of high-severity findings.",
      +                "minimum": 0,
      +                "type": "integer"
      +              },
      +              "info": {
      +                "description": "Number of informational findings.",
      +                "minimum": 0,
      +                "type": "integer"
      +              },
      +              "low": {
      +                "description": "Number of low-severity findings.",
      +                "minimum": 0,
      +                "type": "integer"
      +              },
      +              "medium": {
      +                "description": "Number of medium-severity findings.",
      +                "minimum": 0,
      +                "type": "integer"
      +              }
      +            },
      +            "required": [
      +              "critical",
      +              "high",
      +              "medium",
      +              "low",
      +              "info"
      +            ],
      +            "type": "object"
      +          },
      +          "coverageStatus": {
      +            "description": "Availability of measurements within the requested methods and account scope; not a claim to test every possible website behavior.",
      +            "enum": [
      +              "measured",
      +              "partial",
      +              "unavailable",
      +              "not_applicable"
      +            ],
      +            "type": "string"
      +          },
      +          "executionComplete": {
      +            "description": "Whether all requested pillar runners returned. This is separate from measurement coverage.",
      +            "type": "boolean"
      +          },
      +          "findings": {
      +            "description": "Prioritized findings with evidence, impact, and remediation.",
      +            "items": {
      +              "additionalProperties": false,
      +              "properties": {
      +                "category": {
      +                  "description": "Stable audit category for grouping related findings.",
      +                  "type": "string"
      +                },
      +                "evidence": {
      +                  "description": "Bounded observation that supports the finding.",
      +                  "type": "string"
      +                },
      +                "findingKey": {
      +                  "description": "Deterministic pillar-scoped identity for before/after comparison.",
      +                  "maxLength": 512,
      +                  "minLength": 1,
      +                  "type": "string"
      +                },
      +                "impact": {
      +                  "description": "Why the finding matters to the audited website.",
      +                  "type": "string"
      +                },
      +                "location": {
      +                  "description": "Observed URL or path with credentials and query secrets removed, when available.",
      +                  "type": "string"
      +                },
      +                "remediation": {
      +                  "description": "Concrete recommended fix or mitigation.",
      +                  "type": "string"
      +                },
      +                "severity": {
      +                  "description": "Normalized finding severity: critical, high, medium, low, or info.",
      +                  "type": "string"
      +                },
      +                "title": {
      +                  "description": "Short human-readable finding title.",
      +                  "type": "string"
      +                }
      +              },
      +              "required": [
      +                "findingKey",
      +                "severity",
      +                "title",
      +                "evidence",
      +                "impact",
      +                "remediation",
      +                "category"
      +              ],
      +              "type": "object"
      +            },
      +            "type": "array"
      +          },
      +          "findingsTruncated": {
      +            "description": "True when additional findings exist outside this response.",
      +            "type": "boolean"
      +          },
      +          "grade": {
      +            "description": "Human-readable grade, or null when unavailable.",
      +            "type": [
      +              "string",
      +              "null"
      +            ]
      +          },
      +          "kind": {
      +            "description": "Audit pillar represented by this result.",
      +            "type": "string"
      +          },
      +          "passingChecks": {
      +            "description": "Number of checks that passed or reported protection.",
      +            "minimum": 0,
      +            "type": "integer"
      +          },
      +          "passingFindings": {
      +            "description": "Positive observations retained with their complete evidence.",
      +            "items": {
      +              "additionalProperties": false,
      +              "properties": {
      +                "category": {
      +                  "description": "Stable audit category for grouping related findings.",
      +                  "type": "string"
      +                },
      +                "evidence": {
      +                  "description": "Bounded observation that supports the finding.",
      +                  "type": "string"
      +                },
      +                "findingKey": {
      +                  "description": "Deterministic pillar-scoped identity for before/after comparison.",
      +                  "maxLength": 512,
      +                  "minLength": 1,
      +                  "type": "string"
      +                },
      +                "impact": {
      +                  "description": "Why the finding matters to the audited website.",
      +                  "type": "string"
      +                },
      +                "location": {
      +                  "description": "Observed URL or path with credentials and query secrets removed, when available.",
      +                  "type": "string"
      +                },
      +                "remediation": {
      +                  "description": "Concrete recommended fix or mitigation.",
      +                  "type": "string"
      +                },
      +                "severity": {
      +                  "description": "Normalized finding severity: critical, high, medium, low, or info.",
      +                  "type": "string"
      +                },
      +                "title": {
      +                  "description": "Short human-readable finding title.",
      +                  "type": "string"
      +                }
      +              },
      +              "required": [
      +                "findingKey",
      +                "severity",
      +                "title",
      +                "evidence",
      +                "impact",
      +                "remediation",
      +                "category"
      +              ],
      +              "type": "object"
      +            },
      +            "type": "array"
      +          },
      +          "returnedFindings": {
      +            "description": "Number of findings included in this response.",
      +            "minimum": 0,
      +            "type": "integer"
      +          },
      +          "score": {
      +            "description": "Measured score from 0 to 100, or null when unavailable.",
      +            "type": [
      +              "number",
      +              "null"
      +            ]
      +          },
      +          "status": {
      +            "description": "Completed when requested measurements are available; partial when a requested runner or measurement is unavailable.",
      +            "enum": [
      +              "completed",
      +              "partial"
      +            ],
      +            "type": "string"
      +          },
      +          "target": {
      +            "description": "Canonical audited target.",
      +            "type": "string"
      +          },
      +          "total": {
      +            "description": "Total findings produced before response truncation.",
      +            "minimum": 0,
      +            "type": "integer"
      +          }
      +        },
      +        "required": [
      +          "target",
      +          "kind",
      +          "score",
      +          "grade",
      +          "counts",
      +          "total",
      +          "returnedFindings",
      +          "findingsTruncated",
      +          "passingChecks",
      +          "findings"
      +        ],
      +        "type": "object"
      +      },
      +      {
      +        "additionalProperties": false,
      +        "properties": {
      +          "executionComplete": {
      +            "const": false,
      +            "description": "False until the entire audit result is ready for delivery.",
      +            "type": "boolean"
      +          },
      +          "jobId": {
      +            "description": "Opaque temporary job identifier bound to this account, tool and MCP surface.",
      +            "pattern": "^mj_[A-Za-z0-9_-]{32}$",
      +            "type": "string"
      +          },
      +          "nextAction": {
      +            "const": "poll_same_tool",
      +            "description": "Call this same tool again with pollArguments.",
      +            "type": "string"
      +          },
      +          "pollArguments": {
      +            "additionalProperties": false,
      +            "description": "Arguments for retrieving this existing audit without starting another scan.",
      +            "properties": {
      +              "jobId": {
      +                "description": "The same opaque audit job identifier.",
      +                "pattern": "^mj_[A-Za-z0-9_-]{32}$",
      +                "type": "string"
      +              }
      +            },
      +            "required": [
      +              "jobId"
      +            ],
      +            "type": "object"
      +          },
      +          "retryAfterMs": {
      +            "description": "Suggested delay in milliseconds before polling this job again.",
      +            "minimum": 0,
      +            "type": "integer"
      +          },
      +          "status": {
      +            "const": "running",
      +            "description": "The audit is still executing or completing durable delivery.",
      +            "type": "string"
      +          }
      +        },
      +        "required": [
      +          "status",
      +          "jobId",
      +          "executionComplete",
      +          "nextAction",
      +          "pollArguments",
      +          "retryAfterMs"
      +        ],
      +        "type": "object"
      +      },
      +      {
      +        "additionalProperties": false,
      +        "properties": {
      +          "auditExecuted": {
      +            "const": false,
      +            "description": "This request did not execute a new audit.",
      +            "type": "boolean"
      +          },
      +          "reason": {
      +            "description": "The recoverable job request prerequisite.",
      +            "enum": [
      +              "audit_job_busy",
      +              "audit_job_unavailable",
      +              "audit_job_argument_mismatch",
      +              "audit_job_invalid_arguments"
      +            ],
      +            "type": "string"
      +          },
      +          "status": {
      +            "const": "action_required",
      +            "description": "This request did not start a new audit.",
      +            "type": "string"
      +          },
      +          "usageConsumed": {
      +            "const": false,
      +            "description": "This request did not consume additional audit allowance.",
      +            "type": "boolean"
      +          }
      +        },
      +        "required": [
      +          "status",
      +          "reason",
      +          "auditExecuted",
      +          "usageConsumed"
      +        ],
      +        "type": "object"
      +      }
      +    ],
      +    "type": "object"
      +  },
      +  {
      +    "additionalProperties": false,
      +    "properties": {
      +      "auditExecuted": {
      +        "const": false,
      +        "type": "boolean"
      +      },
      +      "reason": {
      +        "enum": [
      +          "entitlement_required",
      +          "target_verification_required",
      +          "target_reverification_required",
      +          "verification_scope_required",
      +          "usage_limit_reached",
      +          "authorization_consent_required"
      +        ],
      +        "type": "string"
      +      },
      +      "status": {
      +        "const": "action_required",
      +        "type": "string"
      +      },
      +      "usageConsumed": {
      +        "const": false,
      +        "type": "boolean"
      +      }
      +    },
      +    "required": [
      +      "status",
      +      "reason",
      +      "auditExecuted",
      +      "usageConsumed"
      +    ],
      +    "type": "object"
      +  }
      +]
  4. Changed7 schema fields changed
    • addedInput schema / anyOf
      Added value: +[
      +  {
      +    "required": [
      +      "target"
      +    ]
      +  },
      +  {
      +    "maxProperties": 1,
      +    "required": [
      +      "jobId"
      +    ]
      +  }
      +]
    • addedInput schema / properties / jobId
      Added value: +{
      +  "description": "Resume an existing audit by polling this same tool with its returned jobId. Prefer jobId alone; if repeating other arguments, supply every original argument unchanged. Never invent a jobId.",
      +  "pattern": "^mj_[A-Za-z0-9_-]{32}$",
      +  "type": "string"
      +}
    • removedInput schema / required
      Removed value: -[
      -  "target"
      -]
    • removedOutput schema / additionalProperties
      Removed value: -true
    • addedOutput schema / oneOf
      Added value: +[
      +  {
      +    "additionalProperties": true,
      +    "properties": {
      +      "auditDetails": {
      +        "additionalProperties": true,
      +        "description": "Complete available scope, check states and measurement evidence; unmeasured checks are not passes.",
      +        "type": "object"
      +      },
      +      "counts": {
      +        "additionalProperties": false,
      +        "description": "Finding totals grouped by normalized severity.",
      +        "properties": {
      +          "critical": {
      +            "description": "Number of critical findings.",
      +            "minimum": 0,
      +            "type": "integer"
      +          },
      +          "high": {
      +            "description": "Number of high-severity findings.",
      +            "minimum": 0,
      +            "type": "integer"
      +          },
      +          "info": {
      +            "description": "Number of informational findings.",
      +            "minimum": 0,
      +            "type": "integer"
      +          },
      +          "low": {
      +            "description": "Number of low-severity findings.",
      +            "minimum": 0,
      +            "type": "integer"
      +          },
      +          "medium": {
      +            "description": "Number of medium-severity findings.",
      +            "minimum": 0,
      +            "type": "integer"
      +          }
      +        },
      +        "required": [
      +          "critical",
      +          "high",
      +          "medium",
      +          "low",
      +          "info"
      +        ],
      +        "type": "object"
      +      },
      +      "coverageStatus": {
      +        "description": "Availability of measurements within the requested methods and account scope; not a claim to test every possible website behavior.",
      +        "enum": [
      +          "measured",
      +          "partial",
      +          "unavailable",
      +          "not_applicable"
      +        ],
      +        "type": "string"
      +      },
      +      "executionComplete": {
      +        "description": "Whether all requested pillar runners returned. This is separate from measurement coverage.",
      +        "type": "boolean"
      +      },
      +      "findings": {
      +        "description": "Prioritized findings with evidence, impact, and remediation.",
      +        "items": {
      +          "additionalProperties": false,
      +          "properties": {
      +            "category": {
      +              "description": "Stable audit category for grouping related findings.",
      +              "type": "string"
      +            },
      +            "evidence": {
      +              "description": "Bounded observation that supports the finding.",
      +              "type": "string"
      +            },
      +            "findingKey": {
      +              "description": "Deterministic pillar-scoped identity for before/after comparison.",
      +              "maxLength": 512,
      +              "minLength": 1,
      +              "type": "string"
      +            },
      +            "impact": {
      +              "description": "Why the finding matters to the audited website.",
      +              "type": "string"
      +            },
      +            "location": {
      +              "description": "Observed URL or path with credentials and query secrets removed, when available.",
      +              "type": "string"
      +            },
      +            "remediation": {
      +              "description": "Concrete recommended fix or mitigation.",
      +              "type": "string"
      +            },
      +            "severity": {
      +              "description": "Normalized finding severity: critical, high, medium, low, or info.",
      +              "type": "string"
      +            },
      +            "title": {
      +              "description": "Short human-readable finding title.",
      +              "type": "string"
      +            }
      +          },
      +          "required": [
      +            "findingKey",
      +            "severity",
      +            "title",
      +            "evidence",
      +            "impact",
      +            "remediation",
      +            "category"
      +          ],
      +          "type": "object"
      +        },
      +        "type": "array"
      +      },
      +      "findingsTruncated": {
      +        "description": "True when additional findings exist outside this response.",
      +        "type": "boolean"
      +      },
      +      "grade": {
      +        "description": "Human-readable grade, or null when unavailable.",
      +        "type": [
      +          "string",
      +          "null"
      +        ]
      +      },
      +      "kind": {
      +        "description": "Audit pillar represented by this result.",
      +        "type": "string"
      +      },
      +      "passingChecks": {
      +        "description": "Number of checks that passed or reported protection.",
      +        "minimum": 0,
      +        "type": "integer"
      +      },
      +      "passingFindings": {
      +        "description": "Positive observations retained with their complete evidence.",
      +        "items": {
      +          "additionalProperties": false,
      +          "properties": {
      +            "category": {
      +              "description": "Stable audit category for grouping related findings.",
      +              "type": "string"
      +            },
      +            "evidence": {
      +              "description": "Bounded observation that supports the finding.",
      +              "type": "string"
      +            },
      +            "findingKey": {
      +              "description": "Deterministic pillar-scoped identity for before/after comparison.",
      +              "maxLength": 512,
      +              "minLength": 1,
      +              "type": "string"
      +            },
      +            "impact": {
      +              "description": "Why the finding matters to the audited website.",
      +              "type": "string"
      +            },
      +            "location": {
      +              "description": "Observed URL or path with credentials and query secrets removed, when available.",
      +              "type": "string"
      +            },
      +            "remediation": {
      +              "description": "Concrete recommended fix or mitigation.",
      +              "type": "string"
      +            },
      +            "severity": {
      +              "description": "Normalized finding severity: critical, high, medium, low, or info.",
      +              "type": "string"
      +            },
      +            "title": {
      +              "description": "Short human-readable finding title.",
      +              "type": "string"
      +            }
      +          },
      +          "required": [
      +            "findingKey",
      +            "severity",
      +            "title",
      +            "evidence",
      +            "impact",
      +            "remediation",
      +            "category"
      +          ],
      +          "type": "object"
      +        },
      +        "type": "array"
      +      },
      +      "returnedFindings": {
      +        "description": "Number of findings included in this response.",
      +        "minimum": 0,
      +        "type": "integer"
      +      },
      +      "score": {
      +        "description": "Measured score from 0 to 100, or null when unavailable.",
      +        "type": [
      +          "number",
      +          "null"
      +        ]
      +      },
      +      "status": {
      +        "description": "Completed when requested measurements are available; partial when a requested runner or measurement is unavailable.",
      +        "enum": [
      +          "completed",
      +          "partial"
      +        ],
      +        "type": "string"
      +      },
      +      "target": {
      +        "description": "Canonical audited target.",
      +        "type": "string"
      +      },
      +      "total": {
      +        "description": "Total findings produced before response truncation.",
      +        "minimum": 0,
      +        "type": "integer"
      +      }
      +    },
      +    "required": [
      +      "target",
      +      "kind",
      +      "score",
      +      "grade",
      +      "counts",
      +      "total",
      +      "returnedFindings",
      +      "findingsTruncated",
      +      "passingChecks",
      +      "findings"
      +    ],
      +    "type": "object"
      +  },
      +  {
      +    "additionalProperties": false,
      +    "properties": {
      +      "executionComplete": {
      +        "const": false,
      +        "description": "False until the entire audit result is ready for delivery.",
      +        "type": "boolean"
      +      },
      +      "jobId": {
      +        "description": "Opaque temporary job identifier bound to this account, tool and MCP surface.",
      +        "pattern": "^mj_[A-Za-z0-9_-]{32}$",
      +        "type": "string"
      +      },
      +      "nextAction": {
      +        "const": "poll_same_tool",
      +        "description": "Call this same tool again with pollArguments.",
      +        "type": "string"
      +      },
      +      "pollArguments": {
      +        "additionalProperties": false,
      +        "description": "Arguments for retrieving this existing audit without starting another scan.",
      +        "properties": {
      +          "jobId": {
      +            "description": "The same opaque audit job identifier.",
      +            "pattern": "^mj_[A-Za-z0-9_-]{32}$",
      +            "type": "string"
      +          }
      +        },
      +        "required": [
      +          "jobId"
      +        ],
      +        "type": "object"
      +      },
      +      "retryAfterMs": {
      +        "description": "Suggested delay in milliseconds before polling this job again.",
      +        "minimum": 0,
      +        "type": "integer"
      +      },
      +      "status": {
      +        "const": "running",
      +        "description": "The audit is still executing or completing durable delivery.",
      +        "type": "string"
      +      }
      +    },
      +    "required": [
      +      "status",
      +      "jobId",
      +      "executionComplete",
      +      "nextAction",
      +      "pollArguments",
      +      "retryAfterMs"
      +    ],
      +    "type": "object"
      +  },
      +  {
      +    "additionalProperties": false,
      +    "properties": {
      +      "auditExecuted": {
      +        "const": false,
      +        "description": "This request did not execute a new audit.",
      +        "type": "boolean"
      +      },
      +      "reason": {
      +        "description": "The recoverable job request prerequisite.",
      +        "enum": [
      +          "audit_job_busy",
      +          "audit_job_unavailable",
      +          "audit_job_argument_mismatch",
      +          "audit_job_invalid_arguments"
      +        ],
      +        "type": "string"
      +      },
      +      "status": {
      +        "const": "action_required",
      +        "description": "This request did not start a new audit.",
      +        "type": "string"
      +      },
      +      "usageConsumed": {
      +        "const": false,
      +        "description": "This request did not consume additional audit allowance.",
      +        "type": "boolean"
      +      }
      +    },
      +    "required": [
      +      "status",
      +      "reason",
      +      "auditExecuted",
      +      "usageConsumed"
      +    ],
      +    "type": "object"
      +  }
      +]
    • removedOutput schema / properties
      Removed value: -{
      -  "auditDetails": {
      -    "additionalProperties": true,
      -    "description": "Complete available scope, check states and measurement evidence; unmeasured checks are not passes.",
      -    "type": "object"
      -  },
      -  "counts": {
      -    "additionalProperties": false,
      -    "description": "Finding totals grouped by normalized severity.",
      -    "properties": {
      -      "critical": {
      -        "description": "Number of critical findings.",
      -        "minimum": 0,
      -        "type": "integer"
      -      },
      -      "high": {
      -        "description": "Number of high-severity findings.",
      -        "minimum": 0,
      -        "type": "integer"
      -      },
      -      "info": {
      -        "description": "Number of informational findings.",
      -        "minimum": 0,
      -        "type": "integer"
      -      },
      -      "low": {
      -        "description": "Number of low-severity findings.",
      -        "minimum": 0,
      -        "type": "integer"
      -      },
      -      "medium": {
      -        "description": "Number of medium-severity findings.",
      -        "minimum": 0,
      -        "type": "integer"
      -      }
      -    },
      -    "required": [
      -      "critical",
      -      "high",
      -      "medium",
      -      "low",
      -      "info"
      -    ],
      -    "type": "object"
      -  },
      -  "coverageStatus": {
      -    "description": "Availability of measurements within the requested methods and account scope; not a claim to test every possible website behavior.",
      -    "enum": [
      -      "measured",
      -      "partial",
      -      "unavailable",
      -      "not_applicable"
      -    ],
      -    "type": "string"
      -  },
      -  "executionComplete": {
      -    "description": "Whether all requested pillar runners returned. This is separate from measurement coverage.",
      -    "type": "boolean"
      -  },
      -  "findings": {
      -    "description": "Prioritized findings with evidence, impact, and remediation.",
      -    "items": {
      -      "additionalProperties": false,
      -      "properties": {
      -        "category": {
      -          "description": "Stable audit category for grouping related findings.",
      -          "type": "string"
      -        },
      -        "evidence": {
      -          "description": "Bounded observation that supports the finding.",
      -          "type": "string"
      -        },
      -        "findingKey": {
      -          "description": "Deterministic pillar-scoped identity for before/after comparison.",
      -          "maxLength": 512,
      -          "minLength": 1,
      -          "type": "string"
      -        },
      -        "impact": {
      -          "description": "Why the finding matters to the audited website.",
      -          "type": "string"
      -        },
      -        "location": {
      -          "description": "Observed URL or path with credentials and query secrets removed, when available.",
      -          "type": "string"
      -        },
      -        "remediation": {
      -          "description": "Concrete recommended fix or mitigation.",
      -          "type": "string"
      -        },
      -        "severity": {
      -          "description": "Normalized finding severity: critical, high, medium, low, or info.",
      -          "type": "string"
      -        },
      -        "title": {
      -          "description": "Short human-readable finding title.",
      -          "type": "string"
      -        }
      -      },
      -      "required": [
      -        "findingKey",
      -        "severity",
      -        "title",
      -        "evidence",
      -        "impact",
      -        "remediation",
      -        "category"
      -      ],
      -      "type": "object"
      -    },
      -    "type": "array"
      -  },
      -  "findingsTruncated": {
      -    "description": "True when additional findings exist outside this response.",
      -    "type": "boolean"
      -  },
      -  "grade": {
      -    "description": "Human-readable grade, or null when unavailable.",
      -    "type": [
      -      "string",
      -      "null"
      -    ]
      -  },
      -  "kind": {
      -    "description": "Audit pillar represented by this result.",
      -    "type": "string"
      -  },
      -  "passingChecks": {
      -    "description": "Number of checks that passed or reported protection.",
      -    "minimum": 0,
      -    "type": "integer"
      -  },
      -  "passingFindings": {
      -    "description": "Positive observations retained with their complete evidence.",
      -    "items": {
      -      "additionalProperties": false,
      -      "properties": {
      -        "category": {
      -          "description": "Stable audit category for grouping related findings.",
      -          "type": "string"
      -        },
      -        "evidence": {
      -          "description": "Bounded observation that supports the finding.",
      -          "type": "string"
      -        },
      -        "findingKey": {
      -          "description": "Deterministic pillar-scoped identity for before/after comparison.",
      -          "maxLength": 512,
      -          "minLength": 1,
      -          "type": "string"
      -        },
      -        "impact": {
      -          "description": "Why the finding matters to the audited website.",
      -          "type": "string"
      -        },
      -        "location": {
      -          "description": "Observed URL or path with credentials and query secrets removed, when available.",
      -          "type": "string"
      -        },
      -        "remediation": {
      -          "description": "Concrete recommended fix or mitigation.",
      -          "type": "string"
      -        },
      -        "severity": {
      -          "description": "Normalized finding severity: critical, high, medium, low, or info.",
      -          "type": "string"
      -        },
      -        "title": {
      -          "description": "Short human-readable finding title.",
      -          "type": "string"
      -        }
      -      },
      -      "required": [
      -        "findingKey",
      -        "severity",
      -        "title",
      -        "evidence",
      -        "impact",
      -        "remediation",
      -        "category"
      -      ],
      -      "type": "object"
      -    },
      -    "type": "array"
      -  },
      -  "returnedFindings": {
      -    "description": "Number of findings included in this response.",
      -    "minimum": 0,
      -    "type": "integer"
      -  },
      -  "score": {
      -    "description": "Measured score from 0 to 100, or null when unavailable.",
      -    "type": [
      -      "number",
      -      "null"
      -    ]
      -  },
      -  "status": {
      -    "description": "Completed when requested measurements are available; partial when a requested runner or measurement is unavailable.",
      -    "enum": [
      -      "completed",
      -      "partial"
      -    ],
      -    "type": "string"
      -  },
      -  "target": {
      -    "description": "Canonical audited target.",
      -    "type": "string"
      -  },
      -  "total": {
      -    "description": "Total findings produced before response truncation.",
      -    "minimum": 0,
      -    "type": "integer"
      -  }
      -}
    • removedOutput schema / required
      Removed value: -[
      -  "target",
      -  "kind",
      -  "score",
      -  "grade",
      -  "counts",
      -  "total",
      -  "returnedFindings",
      -  "findingsTruncated",
      -  "passingChecks",
      -  "findings"
      -]
  5. Changed10 schema fields changed
    • changedInput schema / properties / modules / description
      Previous value: -"Optional security modules. The default uses public posture signals only. Explicit protected modules require verified-target authorization and remain subject to account and hosted active-scan policy."New value: +"Optional explicit security module selection. Omit to use the plan scope. Protected checks require current target ownership; unavailable engines are reported as unmeasured."
    • addedInput schema / properties / modules / minItems
      Added value: +1
    • addedInput schema / properties / ports
      Added value: +{
      +  "description": "Optional port selection: top, common, all, or comma-separated ports/ranges. Account limits apply; default top.",
      +  "maxLength": 512,
      +  "type": "string"
      +}
    • changedInput schema / properties / profile / description
      Previous value: -"Scan depth. Depth selection (passive/deep/all) is available only on a self-hosted server; the hosted transport runs a fixed non-intrusive baseline."New value: +"Optional security profile included in the account. Omit to run all security modules included in the connected plan."
    • changedInput schema / properties / profile / enum
      Previous value: -[
      -  "baseline"
      -]New value: +[
      +  "passive",
      +  "baseline",
      +  "deep",
      +  "all"
      +]
    • changedOutput schema / properties / auditDetails / description
      Previous value: -"Bounded assessment scope, check states and available measurement evidence; unmeasured checks are not passes."New value: +"Complete available scope, check states and measurement evidence; unmeasured checks are not passes."
    • addedOutput schema / properties / coverageStatus
      Added value: +{
      +  "description": "Availability of measurements within the requested methods and account scope; not a claim to test every possible website behavior.",
      +  "enum": [
      +    "measured",
      +    "partial",
      +    "unavailable",
      +    "not_applicable"
      +  ],
      +  "type": "string"
      +}
    • addedOutput schema / properties / executionComplete
      Added value: +{
      +  "description": "Whether all requested pillar runners returned. This is separate from measurement coverage.",
      +  "type": "boolean"
      +}
    • addedOutput schema / properties / passingFindings
      Added value: +{
      +  "description": "Positive observations retained with their complete evidence.",
      +  "items": {
      +    "additionalProperties": false,
      +    "properties": {
      +      "category": {
      +        "description": "Stable audit category for grouping related findings.",
      +        "type": "string"
      +      },
      +      "evidence": {
      +        "description": "Bounded observation that supports the finding.",
      +        "type": "string"
      +      },
      +      "findingKey": {
      +        "description": "Deterministic pillar-scoped identity for before/after comparison.",
      +        "maxLength": 512,
      +        "minLength": 1,
      +        "type": "string"
      +      },
      +      "impact": {
      +        "description": "Why the finding matters to the audited website.",
      +        "type": "string"
      +      },
      +      "location": {
      +        "description": "Observed URL or path with credentials and query secrets removed, when available.",
      +        "type": "string"
      +      },
      +      "remediation": {
      +        "description": "Concrete recommended fix or mitigation.",
      +        "type": "string"
      +      },
      +      "severity": {
      +        "description": "Normalized finding severity: critical, high, medium, low, or info.",
      +        "type": "string"
      +      },
      +      "title": {
      +        "description": "Short human-readable finding title.",
      +        "type": "string"
      +      }
      +    },
      +    "required": [
      +      "findingKey",
      +      "severity",
      +      "title",
      +      "evidence",
      +      "impact",
      +      "remediation",
      +      "category"
      +    ],
      +    "type": "object"
      +  },
      +  "type": "array"
      +}
    • addedOutput schema / properties / status
      Added value: +{
      +  "description": "Completed when requested measurements are available; partial when a requested runner or measurement is unavailable.",
      +  "enum": [
      +    "completed",
      +    "partial"
      +  ],
      +  "type": "string"
      +}
  6. Changed2 schema fields changed
    • addedOutput schema / properties / auditDetails
      Added value: +{
      +  "additionalProperties": true,
      +  "description": "Bounded assessment scope, check states and available measurement evidence; unmeasured checks are not passes.",
      +  "type": "object"
      +}
    • addedOutput schema / properties / findings / items / properties / location
      Added value: +{
      +  "description": "Observed URL or path with credentials and query secrets removed, when available.",
      +  "type": "string"
      +}
  7. First observed

TDQS

A4.7/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

The description discloses important behavioral traits beyond the annotations: audits can be asynchronous and return 'status: running' with a jobId, polling returns the same audit without consuming extra quota, pollArguments must be copied unchanged, and ownership verification gates protected checks. This prevents the agent from misinterpreting a running status as complete or starting duplicate scans.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is long but every sentence earns its place: it front-loads the core purpose, then covers verification, selection scope, return values, and the crucial polling protocol. There is no filler or redundant restatement of schema fields.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the output schema exists and input schema coverage is complete, the description covers the full operational lifecycle: starting an audit, handling asynchronous results, polling, quota behavior, verification requirements, and reported findings. No critical context for calling this tool correctly is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so parameter details already exist in the schema. The description adds operational meaning beyond the schema by explaining how target and jobId interact in the polling workflow, and by clarifying that profile/module/port selections are subject to account entitlement and that protected selections require verification.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a specific verb ('Audit'), resource ('the website'), and scope ('every security module included in the connected account by default'). It clearly distinguishes the security audit from sibling tools like audit_seo or audit_performance, and the title 'Security audit' is expanded with concrete behavior rather than repeated as a tautology.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description provides detailed usage guidance: start with target, poll with jobId, wait retryAfterMs, copy pollArguments unchanged, and do not start a replacement audit while one is running. It does not explicitly name sibling alternatives or say 'for accessibility use audit_accessibility', but the security-specific scope and the start/poll lifecycle are made clear enough for an agent to select and use the tool correctly.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources