Skip to main content
Glama

Audit Seller Machine Buyability

seller_integrity_audit

Use this after a buyer integration fails, a seller changes a paid route, or before the next paid retry or release. Audit one exact paid GET or POST seller route against buyer-required JSON success paths. GET verifies constructible non-secret input, exact request binding, live x402 and MPP economics, and optional Bazaar eligibility; POST performs static-safe OpenAPI contract analysis and sends no target request. Use payment_offer_preflight instead when you already have one exact callable GET URL and only need its current unpaid offer before buyer authorization, or agent_discoverability_audit for catalog rank and identity. Uses no target credential, signature, or target payment and retains no seller schema, body, or query values.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
routeYesExact paid GET or POST path declared by the seller, without query or template parameters.
methodNoPOST receives static OpenAPI response-contract analysis without sending a target request.GET
originYesCredential-free public HTTPS seller origin on port 443.
referralNoOptional x402 receipt-derived acquisition label. It cannot change payment or delivery.
requireBazaarNoWhen true, missing Bazaar discovery metadata becomes a repair finding for live-probed GET routes.
requiredPathsNoBuyer-required dotted success-response paths that the seller schema must guarantee recursively.

TDQS

A4.7/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description must carry the behavioral disclosure burden. It does so thoroughly: GET performs live verification of x402 and MPP economics, POST performs static-safe OpenAPI analysis and sends no target request, and no target credential, signature, payment, or retained schema/body/query values are used.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is dense but well-structured: usage triggers first, then operation details, then exclusions and safety guarantees. Every sentence adds value and no words are wasted.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a tool with six params, no annotations, and no output schema, the description is remarkably complete. It covers when to use it, what GET vs POST do, which sibling to choose instead, and what data is not used or retained, leaving the agent well-equipped to invoke it correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the schema already documents every parameter. The description adds useful behavioral context, such as 'live x402 and MPP economics' and 'static-safe OpenAPI contract analysis,' but it does not materially expand the per-parameter semantics beyond what the schema already provides.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description is specific: it audits one exact paid GET or POST seller route against buyer-required JSON success paths. It names the resource, verb, and scope, and explicitly distinguishes itself from sibling tools payment_offer_preflight and agent_discoverability_audit.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The first sentence gives explicit trigger conditions: after a buyer integration fails, after a seller changes a paid route, or before the next paid retry or release. It also names alternatives and the exact conditions under which to use them instead.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

TDQS

A4.1/5.0
Disambiguation3/5

Several tools cluster around the same domain: there are multiple audit tools, multiple preflight tools, multiple receipt/settlement tools, and two wallet-policy-conformance tools. The descriptions are carefully distinguished with 'use X instead' notes, but an agent would still need to read closely to separate `agent_discoverability_audit` from `agent_surface_budget_audit` and `seller_integrity_audit` from `payment_offer_preflight`.

Naming Consistency4/5

Most names follow a readable, snake_case pattern with a domain prefix or action stem, such as `morpho_position`, `transaction_receipt`, `wallet_enrich`, and `contract_qualified_search`. The convention is not fully uniform—`read`, `extract`, `scan`, and `schemaforge` are standalone verbs or compounds, and `agent_surface_budget_audit` is a much longer construction—but the style is consistent enough to navigate.

Tool Count3/5

22 tools is at the heavy end of a data-gateway scope, especially since they spread across x402 discovery, Morpho lending, web domain audits, wallet policy, and blockchain receipts. Each tool explains its existence, but the set feels broader than one central data-gateway concern.

Completeness4/5

The tools form a coherent read-only x402/agent-commerce lifecycle: catalog search, discoverability, surface/seller integrity, payment offer preflight, settlement proof, and transaction receipt verification. There are some peripheral tools that do not directly serve x402, and no payment or execution action exists, but the read-only audit gate is intentionally complete and lacks dead ends.