Skip to main content
Glama

GENESIS ProofRelay MCP Verifier

Review vendor risk profile

proofrelay.review_vendor_risk_profile
Read-onlyIdempotent

Review public vendor or MCP server risk metadata for governance signals using hashes and declared boundaries only. This is not legal, security, or procurement certification.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
vendorYes

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault

No arguments

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed6 schema fields changed
    • removedInput schema / $defs
      Removed value: -{
      -  "VendorRiskProfileInput": {
      -    "description": "Public vendor risk profile metadata for review guidance.",
      -    "properties": {
      -      "control_refs": {
      -        "description": "Public-safe control references.",
      -        "items": {
      -          "type": "string"
      -        },
      -        "title": "Control Refs",
      -        "type": "array"
      -      },
      -      "data_boundary": {
      -        "default": "unknown",
      -        "description": "Highest declared data boundary.",
      -        "enum": [
      -          "none",
      -          "metadata",
      -          "pii",
      -          "unknown"
      -        ],
      -        "title": "Data Boundary",
      -        "type": "string"
      -      },
      -      "prior_incident_hash": {
      -        "anyOf": [
      -          {
      -            "type": "string"
      -          },
      -          {
      -            "type": "null"
      -          }
      -        ],
      -        "default": null,
      -        "description": "Optional prior-incident disclosure hash.",
      -        "title": "Prior Incident Hash"
      -      },
      -      "requires_authentication": {
      -        "default": false,
      -        "description": "Auth is required.",
      -        "title": "Requires Authentication",
      -        "type": "boolean"
      -      },
      -      "requires_payment": {
      -        "default": false,
      -        "description": "Payment is required.",
      -        "title": "Requires Payment",
      -        "type": "boolean"
      -      },
      -      "security_docs_hash": {
      -        "anyOf": [
      -          {
      -            "type": "string"
      -          },
      -          {
      -            "type": "null"
      -          }
      -        ],
      -        "default": null,
      -        "description": "Optional security documentation hash.",
      -        "title": "Security Docs Hash"
      -      },
      -      "stores_customer_data": {
      -        "default": false,
      -        "description": "Stores customer data.",
      -        "title": "Stores Customer Data",
      -        "type": "boolean"
      -      },
      -      "subprocessors_hash": {
      -        "anyOf": [
      -          {
      -            "type": "string"
      -          },
      -          {
      -            "type": "null"
      -          }
      -        ],
      -        "default": null,
      -        "description": "Optional subprocessors disclosure hash.",
      -        "title": "Subprocessors Hash"
      -      },
      -      "terms_hash": {
      -        "anyOf": [
      -          {
      -            "type": "string"
      -          },
      -          {
      -            "type": "null"
      -          }
      -        ],
      -        "default": null,
      -        "description": "Optional terms hash.",
      -        "title": "Terms Hash"
      -      },
      -      "vendor_name": {
      -        "description": "Public vendor or MCP server name.",
      -        "title": "Vendor Name",
      -        "type": "string"
      -      },
      -      "vendor_profile_hash": {
      -        "description": "SHA-256 vendor profile hash.",
      -        "title": "Vendor Profile Hash",
      -        "type": "string"
      -      }
      -    },
      -    "required": [
      -      "vendor_name",
      -      "vendor_profile_hash"
      -    ],
      -    "title": "VendorRiskProfileInput",
      -    "type": "object"
      -  }
      -}
    • removedInput schema / properties / vendor / $ref
      Removed value: -"#/$defs/VendorRiskProfileInput"
    • addedInput schema / properties / vendor / properties
      Added value: +{
      +  "control_refs": {
      +    "items": {
      +      "type": "string"
      +    },
      +    "type": "array"
      +  },
      +  "data_boundary": {
      +    "enum": [
      +      "none",
      +      "metadata",
      +      "pii",
      +      "unknown"
      +    ],
      +    "type": "string"
      +  },
      +  "prior_incident_hash": {
      +    "anyOf": [
      +      {
      +        "type": "string"
      +      },
      +      {
      +        "type": "null"
      +      }
      +    ]
      +  },
      +  "requires_authentication": {
      +    "type": "boolean"
      +  },
      +  "requires_payment": {
      +    "type": "boolean"
      +  },
      +  "security_docs_hash": {
      +    "anyOf": [
      +      {
      +        "type": "string"
      +      },
      +      {
      +        "type": "null"
      +      }
      +    ]
      +  },
      +  "stores_customer_data": {
      +    "type": "boolean"
      +  },
      +  "subprocessors_hash": {
      +    "anyOf": [
      +      {
      +        "type": "string"
      +      },
      +      {
      +        "type": "null"
      +      }
      +    ]
      +  },
      +  "terms_hash": {
      +    "anyOf": [
      +      {
      +        "type": "string"
      +      },
      +      {
      +        "type": "null"
      +      }
      +    ]
      +  },
      +  "vendor_name": {
      +    "type": "string"
      +  },
      +  "vendor_profile_hash": {
      +    "type": "string"
      +  }
      +}
    • addedInput schema / properties / vendor / required
      Added value: +[
      +  "vendor_name",
      +  "vendor_profile_hash"
      +]
    • addedInput schema / properties / vendor / type
      Added value: +"object"
    • removedInput schema / title
      Removed value: -"review_vendor_risk_profileArguments"
  2. First observed

TDQS

A4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

The description discloses the tool's scope (public metadata, hashes, declared boundaries) and its non-certification limitation, aligning with the read-only and non-destructive annotations. It could be more explicit about the exact output format, but it is transparent about its intent.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is concise (two sentences) and well-structured, conveying essential information without unnecessary detail. It avoids fluff and directly communicates the tool's purpose and limitations.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

The description gives the tool's purpose and boundaries but does not specify the output structure, expected results, or any preconditions. While the core intent is clear, the lack of output context may leave the agent uncertain about what the tool actually returns.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters2/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The description does not elaborate on the 'vendor' object parameters or their significance. The schema contains many fields (e.g., requires_payment, data_boundary) but the description adds no additional meaning, leaving the agent to infer usage from field names alone.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states that the tool reviews public vendor or MCP server risk metadata for governance signals, with explicit constraints on using hashes and declared boundaries. It differentiates itself from certification tasks, making its purpose specific and distinct from sibling tools.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description provides context on when to use the tool (for governance signals) and explicitly notes what it is not (legal, security, or procurement certification). However, it does not directly mention alternative tools or specific scenarios beyond the core review purpose.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources