Causara Economic Control
Server Details
Economic exposure and control decisions for autonomous AI actions in Shadow Mode.
- Status
- Healthy
- Last Tested
- Transport
- Streamable HTTP · MCP 2025-11-25
- URL
TDQS
Scored across 3 tools
Each tool has a clearly distinct purpose: evaluate an action, retrieve model metadata, and normalize business context. The descriptions explicitly clarify what each tool does not do, eliminating overlap.
All tool names follow a consistent snake_case verb_noun pattern (evaluate_agent_action, get_control_model, normalize_business_context). The convention is predictable and readable.
Three tools are well-scoped for a focused economic-control engine. Each tool serves a distinct, necessary function without redundancy.
The core workflow (normalize context, check model, evaluate action) is fully covered. However, the mentioned Shadow risk ledger has no corresponding read/query tool, which is a minor gap.
Available Tools
3 toolsevaluate_agent_actionEvaluate agent economic exposureBInspect
Run a proposed autonomous AI action through Causara's frozen Shadow Mode economic-control engine. Returns downstream dependency path, economic exposure, potential loss, confidence, and an ALLOW/REVIEW/ESCALATE/BLOCK recommendation. Causara does not execute or block the proposed business action. The evaluation is recorded in Causara's Shadow risk ledger.
| Name | Required | Description | Default |
|---|---|---|---|
| event | Yes | ||
| data_source | No | ||
| business_context | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations mark this as non-readOnly and non-idempotent, but the description supplies the missing explanation: the evaluation is recorded in Causara's Shadow risk ledger (why it is a write), it does not execute or block the underlying business action (limits blast radius), and it is a 'frozen' engine (deterministic policy). That is real context beyond the annotation flags, though rate limits, auth, and re-run behavior are unstated.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Four sentences, each carrying distinct information: what it does, what it returns, what it does not do, and the side effect. The return values are front-loaded ahead of the caveats. Slight deduction for the marketing-flavored phrasing 'frozen Shadow Mode economic-control engine'.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With no output schema, the description correctly enumerates the return payload (dependency path, exposure, potential loss, confidence, recommendation). But for a tool with a large nested input schema and zero schema descriptions, the description never explains how to construct the required event and business_context inputs, leaving a significant gap for an agent.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 0% across three top-level parameters containing deeply nested required objects (event, business_context.policy, inventory, production, commercial). The description says nothing about how to populate event or business_context, what action_type values mean, or what data_source is for, so it fails to compensate for the documentation gap.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description gives a specific verb and resource: it runs a proposed autonomous AI action through a named economic-control engine and returns a specific decision artifact (ALLOW/REVIEW/ESCALATE/BLOCK). That is far more than a restatement of the name. It stops short of a 5 because it never positions itself against the siblings normalize_business_context and get_control_model, which an agent may need to call first.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Usage is implied by 'Run a proposed autonomous AI action', and the sentence 'Causara does not execute or block the proposed business action' usefully bounds what invoking this tool accomplishes. However, there is no explicit when-to-use guidance, no statement of prerequisites, and no mention of the sibling tools or the ordering between them.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
get_control_modelGet Causara control modelARead-onlyIdempotentInspect
Return the live Causara V2.0 Shadow Mode model metadata, including supported action routes and frozen validation status. Use this before evaluation when you need to check whether an action type is supported.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint=true, idempotentHint=true, and destructiveHint=false, so the safety profile is fully covered. The description adds freshness context ('live') and the notion of a 'frozen validation status', which is useful but not deep behavioral disclosure such as caching or staleness guarantees.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two sentences, no filler. The return content is front-loaded and the usage condition follows, so an agent can decide and act immediately.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With no output schema, the description carries the return-value burden and does so by naming the payload contents (action routes, validation status). Combined with annotations covering safety and a trivial empty input schema, the definition is nearly self-sufficient; only the exact response shape remains unspecified.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The tool takes zero parameters, so the baseline of 4 applies. There are no inputs whose semantics need explaining in the description.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb+resource (get the control model) and enumerates the returned content: model metadata, supported action routes, and frozen validation status. It does not name the sibling tools, but the 'before evaluation' phrasing implicitly anchors it against evaluate_agent_action.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Gives a clear trigger condition: use it before evaluation when you need to check whether an action type is supported. No explicit when-not or named alternatives, but the usage context is unambiguous for a zero-arg lookup tool.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
normalize_business_contextNormalize business contextARead-onlyIdempotentInspect
Validate and normalize a structured business-context CSV into Causara's canonical economic context. This does not evaluate or execute an AI action. Use it when source data is available as a field/value or single-row CSV export.
| Name | Required | Description | Default |
|---|---|---|---|
| csv | Yes | Business context CSV text. | |
| filename | No | agent-business-context.csv |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint, idempotentHint, destructiveHint=false and openWorldHint=false, so safety behavior is covered. The description adds that it validates (i.e., can reject input) and clarifies the tool is not an evaluation/execution step, but says nothing about what validation failures look like or what the canonical output contains. Adequate but modest added value over the annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Three short sentences, front-loaded with the core verb/resource and output, then the negative scope, then the usage trigger. No filler or redundancy.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a two-parameter, read-only, idempotent tool with no output schema, the description covers purpose, scope, and trigger well. The remaining gap is minor: it doesn't hint at the return shape (e.g., the canonical context object) or what a validation error yields, but nothing critical for invoking the tool is missing.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 50%: the required 'csv' parameter is documented, but 'filename' is not described in the schema or the description. The phrase 'field/value or single-row CSV export' does add real meaning about the accepted CSV shape beyond the generic 'Business context CSV text' schema text, which keeps this above a pure baseline.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States specific verbs (validate, normalize), the input resource (structured business-context CSV), and the output target (Causara's canonical economic context). The negation 'does not evaluate or execute an AI action' implicitly separates it from the evaluate_agent_action sibling, though it never names it directly.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Gives a clear triggering condition: 'Use it when source data is available as a field/value or single-row CSV export.' It also carves out the negative case (not for evaluating or executing actions). No explicit sibling routing, but the context is sufficient to select the tool.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
3 tool updates
- First observed
evaluate_agent_action - First observed
get_control_model - First observed
normalize_business_context
Related MCP Connectors
Autonomous Decision Intelligence for evaluating economic decisions before value is committed.
Decision-assurance for AI agents: an auditable action boundary + receipt before it acts.
Deterministic pre-trade risk checks for autonomous AI trading agents.
Reversibility intelligence and durable exit evidence for AI agents before real-world commitments.
Related MCP Servers
- FlicenseNot gradedqualityAmaintenanceThe Control Plane for Autonomous AI Enforce policy before execution, require human approvals where risk demands it, and keep a full audit trail — from first action to final result.510-
- AlicenseNot gradedqualityBmaintenanceEnables autonomous agents to detect under-specified user goals, gauge reversibility and risk, and present minimal multiple-choice clarifications before committing to high-stakes execution.7MIT
- AlicenseNot gradedqualityBmaintenanceA public-safe research prototype for controlling AI-agent tool actions with deterministic policy, risk-based human approval, time-bound authorization and a tamper-evident audit chain.1MIT
- AlicenseAqualityAmaintenanceRuntime budget authority for autonomous agents - a set of tools to check, reserve, spend, and release budget before and after every costly, risky operation. The agent asks "can I afford this?" before acting, and reports what it actually used afterward.973 npmApache 2.0
Glama MCP Gateway
Add one secure layer between your agents and this server.