Skip to main content
Glama

SQLGuard — Execution Certificate Firewall

Pilot Challenge — PRIMARY wealth Exact $100.00 unlock

sqlguard_challenge
Read-onlyIdempotent

PRIMARY agent buy path. Free POST /v1/challenge with mutating SQL → DENY + deny_id. Exact USDC $100.00 via POST /v1/challenge/unlock (402 amount 100000000) opens 500 PASS / 7d. Alt: Gateway invoice $299/$499/$1999. Session/Cert/micro OFF TABLE as primary. Probe FREE tip — never authorizes.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
sqlNoOptional mutating SQL to preview; if set, returns mint body ready for POST /v1/challenge
agent_idYesAgent or wallet id that will unlock / claim
schema_ddlNoOptional schema_ddl paired with sql

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
mintNo
unlockNo
productNo

TDQS

A4.4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint=true and idempotentHint=true; the description adds useful behavior beyond that: the free POST path with mutating SQL results in DENY + deny_id, the exact 402 amount 100000000 is required, and the unlock grants 500 PASS for 7 days. No contradiction with annotations.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is dense and front-loaded with the most important routing information: 'PRIMARY agent buy path.' Every sentence carries either a price, an outcome, or an alternative. It is highly compact, though some jargon like 'OFF TABLE' and 'Tip' makes it slightly less immediately readable.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given rich annotations and an output schema, the description covers what an agent needs: exact pricing, endpoint behavior, pass duration, and sibling-tool alternatives. It also explicitly states the Probe alternative never authorizes, which helps the agent avoid misuse.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the schema already explains the three parameters. The description adds context around sql as 'mutating SQL' and mentions the amount 100000000, but it doesn't materially deepen meaning for agent_id or schema_ddl beyond what the schema already provides.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a specific action and resource: 'PRIMARY agent buy path' and 'Exact USDC $100.00 via POST /v1/challenge/unlock ... opens 500 PASS / 7d.' It clearly identifies this tool as the primary challenge-buy path and distinguishes it from the alternative Gateway invoice and Probe paths.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It explicitly says when to use this tool — as the PRIMARY agent buy path — and names alternatives: 'Alt: Gateway invoice $299/$499/$1999' and 'Probe FREE tip — never authorizes.' It also states Session/Cert/micro are 'OFF TABLE as primary,' giving an agent clear routing guidance.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

TDQS

B3.1/5.0
Disambiguation1/5

Multiple tools occupy the same job: challenge and pilot both sell the $100/7-day PASS; buy/catalog/cert/session/workday/validate are all legacy prepaid paths; handshake/protocol/require/sdk all provide onboarding/compliance guidance. Descriptions add PRIMARY/LEGACY labels, but an agent still has to parse heavy cross-references to avoid picking the wrong payment or authorization tool.

Naming Consistency4/5

All tool names share the consistent sqlguard_ prefix and lower_snake_case style, and each name maps to a recognizable concept. However, the set mixes noun labels (denials, gravity, session) with verb labels (bind, buy, verify), so it is not a strict verb_noun API convention.

Tool Count3/5

24 tools sits at the top of the 'heavy but borderline' range. Many could be collapsed because the legacy prepaid paths (session, workday, cert, buy, catalog, validate) are explicitly marked OFF TABLE for the primary wealth path, leaving redundant surface area.

Completeness4/5

The core lifecycle is well covered: handshake/onboarding, challenge/pilot unlock, bind/gate/verify pre-execution checks, denials inventory, effects verification, and client status. Minor gaps exist only around explicit invoice/refund/revocation tooling, but those appear to be handled externally or by expiry.