audit_query
Query an agent audit trail (public verification fields only: hashes, decision, timestamps).
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| limit | No | ||
| client_id | Yes | ||
| target_asset | No |
Query an agent audit trail (public verification fields only: hashes, decision, timestamps).
| Name | Required | Description | Default |
|---|---|---|---|
| limit | No | ||
| client_id | Yes | ||
| target_asset | No |
Changes observed during successful MCP inspections.
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations and no output schema, the description carries the full burden. It does disclose the scope of returned data (hashes, decision, timestamps) and implicitly that this is a read-only lookup, which is genuine value, but it says nothing about auth/permission requirements, pagination, ordering, or result size limits.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
A single front-loaded sentence with no filler; the resource and the scoping constraint are stated immediately.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a tool with no annotations, no output schema, and three fully undocumented parameters, the description is thin. An agent still lacks parameter meanings, pagination behavior, and any indication of required permissions.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 0%, and the description never explains client_id, limit, or target_asset. The listed fields (hashes, decision, timestamps) are output concepts, not parameters, so the description does not compensate for the undocumented schema.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb and resource ('Query an agent audit trail') and scopes the returned data ('public verification fields only: hashes, decision, timestamps'). It does not explicitly differentiate itself from the nearby audit_verify or evidence_bundle siblings, but the purpose is unambiguous.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
No guidance on when to use this vs audit_verify, evidence_bundle, or the other audit/compliance siblings is given. The name implies a read/query operation, but there are no stated prerequisites, exclusions, or alternative routing.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Add one secure layer between your agents and this server.