Skip to main content
Glama

handoff — agent swarm coordination

Send order

send_order
Destructive

Send an ORDER down a project's chain of command. You must control the sender (SIGN as it). The hierarchy gates it: an agent may order anyone BENEATH it; orchestrators may order anyone, any time. Delivered to the recipient as a priority directive (priority 0 = top of chain). AUTH — SIGN THE REQUEST. Ed25519 over the handoff-signed-req statement, headers X-Agent-Id / X-Signature / X-Timestamp, so nothing secret crosses the wire; scripts/handoff-lib.mjs restFetch is the reference signer, and handoff enroll <id> mints your signing key if you have none. TRANSPORT: signing works on BOTH MCP transports — the per-POST /mcp one, and the legacy SSE bridge (GET /mcp + POST /mcp/messages), where each message POST carries its own signature (sign the path /mcp/messages WITHOUT the ?sessionId query; signatures are single-use on that channel, so sign each message rather than replaying one).

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
toYes
fromYesthe SENDER agent (you must be able to sign as it)
orderYes
task_idNo
request_idYes

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

A4.2/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Goes well beyond the annotations by disclosing mandatory Ed25519 signing, the exact headers, the reference signer script, key enrollment, and transport-specific signing rules (including single-use signatures on the legacy SSE channel). This is exactly the operational context an agent needs before invoking a destructive, non-idempotent mutation.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness3/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loads purpose and the hierarchy rule well, but the AUTH/TRANSPORT sections sprawl into parenthetical asides and inline script paths that are dense and hard to scan. Most content earns its place, but the transport paragraph in particular could be tightened considerably.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given no output schema and a mutation tool, the description covers the critical unknowns — authentication, authorization gating, delivery semantics, and transport caveats — so an agent can call it successfully. The remaining gap is the purpose of request_id and task_id, which are never explained.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is only 20%, and only two of five parameters get attention: 'from' is clarified as the signer identity and 'order' gains the priority-0 convention. 'request_id', 'task_id' and 'to' remain undocumented in both schema and description, so the description only partially compensates for the coverage gap.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource — 'Send an ORDER down a project's chain of command' — and immediately differentiates it from broadcast-style siblings by describing it as a directive delivered to a specific recipient. An agent can distinguish it from send_message/send_signal without opening other schemas.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly states who may send to whom ('an agent may order anyone BENEATH it; orchestrators may order anyone') and gives the priority convention (priority 0 = top of chain). It does not name sibling alternatives like send_signal or send_message, but the gating conditions are clear enough to select correctly.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources