Skip to main content
Glama

update_finding

Idempotent

Update hosted update finding using privacy-filtered project metadata.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
detailsNo
findingIdYes
projectIdYes
sessionIdNo
executionIdNo
idempotencyKeyYes
expectedVersionYes

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

C2.8/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already establish that this is a non-read-only, non-destructive, idempotent operation, so the description has a lighter burden. The 'privacy-filtered project metadata' phrase adds a hint about data handling, but it is vague, and the description does not clarify expectedVersion or idempotency behavior or describe what happens after the update.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness3/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is a single sentence with no wasted words, and the action is front-loaded. However, for a 7-parameter tool with a nested object and no parameter explanations, this reads as under-specification rather than appropriately concise.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness2/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

This is a complex update requiring idempotencyKey and expectedVersion, with no output schema and no parameter documentation. The description does not explain concurrency semantics, allowed detail values, or when to choose sibling tools, so an agent cannot reliably form a correct call.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters2/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

With 0% schema description coverage, the description must provide parameter meaning, but it only gestures at 'project metadata'. It does not explain details.status/summary/referenceIds, idempotencyKey, expectedVersion, sessionId, or executionId, leaving an agent dependent on raw schema constraints.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a specific action ('Update') and resource ('finding'), which is enough to distinguish it from create_finding, delete_finding, and list_findings. However, the phrasing 'hosted update finding' is awkward and 'using privacy-filtered project metadata' is unexplained, so it does not earn a 5.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

There is no guidance on when to use this tool versus create_finding, promote_insight_to_finding, or delete_finding. No prerequisites, exclusions, or alternative conditions are provided; only the verb itself implies the use case.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources