Skip to main content
Glama

Fingerprint MCP tools

marketnow_fingerprint_tool
Read-onlyIdempotent

Cryptographically fingerprint MCP tool definitions (OWASP MCP Cheat Sheet: 'verify tool descriptions haven't changed'). Computes RFC 8785 JCS + sha256 per tool plus a manifest fingerprint for the whole tools/list surface. Pass a previous manifest in 'pinned' to get a drift report (added/removed/changed) — the core defense against tool poisoning and rug-pull redefinitions.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
toolsYesTool definitions from tools/list: [{name, description, inputSchema}]
pinnedNoOptional: previous manifest {tools:[{name, fingerprint_sha256}]} from an earlier fingerprint run — enables drift detection

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

A4.4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already establish the safe read-only, idempotent, non-destructive profile, so the description only needs to add context beyond that — which it does by disclosing the deterministic algorithm (JCS + sha256), the two levels of output (per-tool plus whole-manifest), and the drift categories returned. It stops short of describing error handling or what a changed-vs-added entry looks like structurally.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Three sentences, all load-bearing: the first defines the operation and standard, the second defines the output surface, the third defines the optional drift behavior. Front-loaded with the core action before the conditional 'pinned' path.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the description usefully characterizes the return structure (per-tool fingerprint, manifest fingerprint, drift report), which is what an agent needs to interpret results. Nested-object handling is covered by the schema and the description's shape hints. It could say slightly more about the fingerprint value format or failure cases, but nothing essential is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the baseline is 3, but the description adds genuine meaning beyond the schema: it explains that 'pinned' is a previous manifest and that supplying it yields a drift report broken into added/removed/changed. The 'tools' parameter is left to the schema, which already documents its shape.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a precise verb+resource ('Cryptographically fingerprint MCP tool definitions') and immediately scopes what is fingerprinted (RFC 8785 JCS + sha256 per tool, plus a manifest fingerprint for the whole tools/list surface). It is instantly distinguishable from sibling tools like verify_trust or check_revocation, which operate on different objects.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It gives a clear trigger ('verify tool descriptions haven't changed') and spells out the conditional behavior that selects the drift-report path via the 'pinned' argument. It does not name any sibling alternative, but the siblings occupy unrelated domains, so the omission is minor.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.