Skip to main content
Glama

FHI MCP Server Security Audit

SEC Filing Delta

sec_material_event_delta

New SEC 8-K, 6-K, and late-filing evidence since a cursor date; accepts a ticker or CIK. ($0.01 USDC on Base)

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
cikNo
sinceYes
tickerNo

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

B3.3/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the full burden, and it does add one genuinely useful behavioral fact: the cost ($0.01 USDC on Base). It says nothing about rate limits, whether payment must be pre-authorized, or what happens when both ticker and cik are supplied, so coverage is partial at best.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

A single tight sentence with the core capability front-loaded and the cost deferred to a trailing parenthetical. Nothing is wasted, though the terseness is part of why the semantic gaps above remain.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness2/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

No output schema and no annotations, yet the description omits the single most important detail for a delta endpoint: whether the response returns a next cursor and how to advance polling. Return shape, pagination and error behavior are all unspecified for a 3-parameter tool.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 0%, so the description must compensate; it does name all three parameters (ticker, cik, since) and gives 'since' a cursor-date meaning. However it omits date/cursor formats and does not resolve whether ticker and cik are alternatives or can be combined, leaving real ambiguity.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource: retrieves new SEC 8-K, 6-K and late-filing evidence, scoped to an incremental window. The filing-type list makes it clearly distinct from siblings like domain_change_evidence or package_install_preflight, though it never names a sibling directly.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The phrase 'since a cursor date' implies incremental polling usage without saying so explicitly, and there is no when-to-use/when-not guidance or named alternative. An agent can infer the delta pattern but must guess at the surrounding workflow.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources