Skip to main content
Glama

XposedOrNot Breach Intelligence

Summarize Domain Breach Exposure

domain_breach_summary
Read-onlyIdempotent

Get an aggregate breach summary for a domain, including the number of breaches, affected email accounts, pastes, and the most recent breach date. Returns only counts, not individual email addresses.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
domainYesDomain to summarize breaches for

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

A3.8/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint, idempotentHint and non-destructive, so the safety profile is covered. The description adds genuinely useful scope context: it enumerates what the aggregate contains (breach count, affected accounts, pastes, most recent date) and explicitly notes it returns only counts, not individual email addresses.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two tight sentences, front-loaded with the aggregate purpose and followed by the return-scope caveat. No filler and every clause carries information.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the description compensates by naming the returned metrics and clarifying the count-only granularity. For a single-parameter read tool with full annotation coverage this is nearly complete; only edge behavior (e.g. unknown or malformed domains) is unstated.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100% for the single 'domain' parameter, so the schema already documents it. The description adds only the implied notion of domain scoping, no format or syntax detail beyond the schema, making the baseline 3 appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb (aggregate/summarize) and resource (breach exposure for a domain), and the domain-level scope clearly separates it from check_email_breaches and list_breaches. It does not explicitly distinguish itself from the closest cousins, get_breach_analytics and get_breach_metrics, so an agent must infer the boundary.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Usage is only implied: an agent can infer this is the domain-level rollup rather than a per-email or raw-list lookup. There is no explicit when-to-use, when-not-to-use, or naming of an alternative sibling, which matters here given five closely related breach tools.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.