Skip to main content
Glama

Nullcone Threat Intelligence

is_ioc_revoked

Check whether an IOC has been revoked. O(1) in-process lookup.

Use this before acting on any cached threat intelligence to ensure the
IOC has not been retracted since it was loaded.

Args:
    value_hash: SHA256 of {ioc_type}:{value.lower()}.

Returns:
    revoked: bool
    event:   Revocation event details if revoked, null otherwise.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
value_hashYes

TDQS

A4.6/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations provided, the description carries the full burden of behavioral disclosure. It mentions performance ('O(1) in-process lookup'), which implies a non-destructive, fast read operation. It also specifies the return format: 'revoked: bool, event: Revocation event details if revoked, null otherwise.' This gives the agent expectations about the response. It does not discuss side effects (likely none) or authentication, but for a read-only check, this is sufficient.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is concise, structured with clear 'Args' and 'Returns' sections, and every sentence adds value. It avoids redundancy and presents the necessary information in a scannable manner. The use of code formatting for the parameter definition enhances readability.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the simplicity of the tool (one parameter, no output schema), the description is complete. It explains the purpose, when to use it, the parameters, and the return value. The tool's behavior is well-specified, and nothing critical is missing for the agent to invoke it correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters5/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The schema only says 'Value Hash' with no explanation, but the description adds crucial detail: 'value_hash: SHA256 of {ioc_type}:{value.lower()}.' This tells the agent the exact format required, which is essential for correct invocation. Since schema coverage is 0%, the description fully compensates and goes beyond the schema's minimal information.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool's purpose: 'Check whether an IOC has been revoked.' It identifies the resource (IOC) and the action (check revocation status), and it differentiates from siblings like 'check_freshness' and 'lookup_ioc' by focusing specifically on revocation. The inclusion of 'O(1) in-process lookup' adds performance context, further clarifying its specific role.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description provides explicit when-to-use guidance: 'Use this before acting on any cached threat intelligence to ensure the IOC has not been retracted since it was loaded.' This clearly states the intended context and purpose. However, it does not mention when not to use it or suggest alternatives, though siblings are available. The lack of exclusions leaves room for ambiguity, but the primary usage is well-communicated.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

TDQS

A3.9/5.0
Disambiguation4/5

Most tools have clearly distinct purposes, but there is notable overlap among threat-fetching methods: get_new_threats, poll_since, and drain_subscription all retrieve new threats via different mechanisms, and several stats tools (get_stats, freshness_limits, prompt_cache_stats) serve similar informational roles. Overall, descriptions help disambiguate, but a few tools could be confused.

Naming Consistency3/5

The naming is predominantly snake_case, but mixes verb_noun (check_freshness, submit_ioc), noun phrases (family_threats, freshness_limits), and even a question (is_ioc_revoked). 'unsubscribe' breaks the pattern of other subscription tools (subscribe_threats, drain_subscription). This inconsistency is noticeable though still readable.

Tool Count3/5

30 tools is on the heavy side for a single MCP server, exceeding the typical 15-tool comfort zone. However, the server covers a broad domain—IOC submission, retrieval, subscriptions, freshness tracking, prompt/skill scanning, and registry monitoring—so the large number is somewhat justified by the scope.

Completeness4/5

The tool surface covers the full threat intelligence lifecycle: submit (submit_ioc, submit_batch), query (lookup_ioc, search_by_type, recent_threats, family_threats), subscribe (subscribe_threats, drain_subscription), update (report_detection, vote_false_positive), and revoke (revoke_ioc). Minor gaps exist, such as the absence of a direct delete or update signature tool and no get-by-signature-id endpoint, but these are manageable for agents.