Skip to main content
Glama

agent_coverage_crosswalk

What one framework already evidences of another

Given a framework you already hold and one you are working toward, returns which of the target's controls your existing evidence already covers, which remain as gaps, and the reasoning for every claim.

Example: source='SOC 2', target='ISO 27001:2022'.

Mappings are derived judgements, not text lifted from either standard, and each has survived an adversarial verification pass. Where no mappings exist between the pair, the response says so explicitly rather than reporting zero coverage, because an absence of data is not a coverage of zero.

PAID PER CALL, $0.015 over x402 (USDC on Base). Called without payment it answers 402 with a PAYMENT-REQUIRED challenge carrying the amount, asset and address; a Professional API key is served free instead. Free without payment or key: agent_crosswalk_pairs lists every released pair, agent_search_frameworks and agent_get_framework cover the catalogue.

Responses:

200: Successful Response (Success Response) Content-Type: application/json

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
sourceYesFramework you already hold, e.g. 'SOC 2'
targetYesFramework you are working toward, e.g. 'ISO 27001:2022'
min_confidenceNohigh, medium or lowhigh

Schema Changelog

Changes observed during successful MCP inspections.

  1. Added

TDQS

A4.1/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the full burden and does so well: it discloses the cost ($0.015 per call via x402/USDC on Base), the exact failure behavior of an unpaid call (402 with a PAYMENT-REQUIRED challenge carrying amount, asset and address), the free-key path, and the guarantees on the data (derived judgements that survived adversarial verification). It also pre-empts a likely misread by stating that an absent mapping is reported explicitly rather than as zero coverage.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The critical information (what it returns, example, derivation caveat, pricing) is front-loaded, and the alternative/free routing is appropriately placed last. The opening fragment and the dense payment clause add some reader burden, but nearly every sentence earns its place.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

There is no output schema, and the description does describe the shape of the result (covered controls, gaps, per-claim reasoning, and the no-mapping case). Payment mechanics and free alternatives are covered, which is unusually complete. It is only marginally short on how the response is structured or paginated, which prevents a 5.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the schema already documents source, target and min_confidence with examples. The description repeats the source/target framing and adds nothing about the semantics of min_confidence (what high/medium/low actually filter). Baseline 3 is appropriate when the schema does the heavy lifting.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a specific computation: given a held framework and a target framework, it returns which of the target's controls are already evidenced, which are gaps, and the reasoning behind each claim. It is far more than a restatement of the name and includes a concrete example pair. It names some siblings as free alternatives but does not distinguish itself from close siblings like agent_cross_framework_map or agent_combined_coverage, which keeps it off a 5.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It clearly frames the use case ('a framework you already hold and one you are working toward') and routes users of the free-tier catalogue to agent_crosswalk_pairs, agent_search_frameworks and agent_get_framework. However, it does not say when to prefer this over the many other crosswalk/mapping siblings (agent_cross_framework_map, agent_crosswalk_pair, agent_combined_coverage), so no explicit exclusions are given.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.