Skip to main content
Glama

handoff — agent swarm coordination

Create mod

create_mod

Create a mod in the library — a tool, MCP server, skill, workflow, rules, or identity your agents can be granted. Creating does NOT attach it to anyone: follow with grant_mod. AUTH: SIGN the request as an agent (X-Agent-Id/X-Signature/X-Timestamp), or use your owner session.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
urlNowhere the tool/MCP lives (an endpoint, a package, a repo)
kindNodefault 'tool'. skill/workflow payloads are {steps:[{checks:[]}]}; identity payloads are {as_agent_id, scope?, ttl_s?}
nameYesshort display name, e.g. "tts-api"
specNomachine-readable shape (an MCP tool schema, an OpenAPI fragment) — public
itemsNomod ids this collection bundles — a grant of the collection delivers every leaf
payloadNothe substance the grantee loads: config, credentials, instructions. Mark sensitive:true when it holds a secret
sensitiveNotrue strips the payload from every public read; only the creator, grantees and buyers ever see it
enc_pubkeyNoX25519 public key to seal v1 to; omit to use the one on your account
descriptionNowhat it is for — shown in every public listing

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

A4.2/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare the safety profile (not read-only, not destructive, not idempotent), so the description's real contribution is the AUTH contract — sign as an agent via X-Agent-Id/X-Signature/X-Timestamp or use an owner session — which is not derivable from any structured field. It also reinforces the side-effect boundary (no grant is created), though it says nothing about rate limits or what happens on duplicate names.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two sentences, front-loaded with the core action and its scope boundary, followed by the auth requirement. No filler, and each sentence carries distinct information an agent needs before calling.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a 9-parameter mutation with nested payload/spec objects and no output schema, the description covers purpose, the create/grant relationship, and the auth requirement well. It is slightly thin on what the call returns (presumably a mod id to feed into grant_mod) and on duplicate-name behavior, which matters for a non-idempotent create.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100% and each of the 9 parameters already carries a substantive description, so the schema does the heavy lifting. The description's kind enumeration merely restates the enum in the schema and adds no syntax, format, or default guidance beyond it.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

Names a specific verb (create) and resource (mod), enumerates the concrete kinds it can hold (tool, MCP server, skill, workflow, rules, identity), and explicitly disambiguates from the sibling grant_mod by stating that creation does not attach the mod to anyone.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly routes the agent to the next step ('follow with grant_mod') and clarifies the scope boundary of this call, which is the main ambiguity for a create-vs-grant pair. It stops short of stating when-not to use it or contrasting with get_mods/revoke_mod beyond the single hand-off note.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources