password_check
Combined password strength + breach check
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| password | Yes | ||
| check_breach | No |
Combined password strength + breach check
| Name | Required | Description | Default |
|---|---|---|---|
| password | Yes | ||
| check_breach | No |
Changes observed during successful MCP inspections.
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full burden of behavioral disclosure, yet it only names the check types. It does not state whether the password is sent externally, hashed, stored, or any security/privacy behavior—critical details for a password tool.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The one-line fragment is front-loaded and free of waste, but it is under-specified for the tool's security-sensitive complexity. Conciseness is achieved at the cost of necessary detail.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given no annotations, no output schema, 0% parameter coverage, and two parameters including a security-sensitive password input, the description is completely inadequate. An agent lacks the context needed to invoke it responsibly.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 0%, and the description does not explain either parameter. It fails to compensate for the missing schema documentation.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's function: a combined password strength and breach check. It implicitly distinguishes itself from separate sibling tools (password, password_breach) by being a combined check, but it does not name those siblings explicitly.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The word 'combined' implies the tool should be used when an agent wants both strength and breach checks in one call, but there is no explicit when-to-use guidance, no conditions, and no named alternatives. This is minimal implied usage.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.