Skip to main content
Glama

opencode-workbench

Inspect a Linux target

inspect_target
Read-onlyIdempotent

Probe one Linux machine — this host (local) or a remote host over SSH (ssh) — and report its OS, kernel, architecture, package manager, Node/npm, OpenCode, Docker, and per-tool detection flags, plus the names (never values) of credentials present. Read-only: one shell probe, changes nothing. Use it to see what a clone would touch, then plan_clone to turn that into an ordered plan; for a first-time end-to-end provision use bootstrap_host. It installs nothing.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
targetYesThe machine to operate on: this host (local) or a remote host over SSH (ssh).

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
hasYesDetection flags for git, curl, node, npm, corepack, pnpm, docker, uv, gh, opencode, sudo.
archNoCPU architecture (e.g. x86_64, aarch64).
homeYesHome directory on the target.
osIdNoOS identifier (e.g. ubuntu, debian, rhel).
userYesDetected user on the target.
kernelNoKernel name and release.
osNameNoHuman-readable OS name.
configDirYesOpenCode config directory on the target.
osVersionNoOS version string.
envPresentNoSpace-separated names of credentials present on the target (values are never read).
npmModulesNonpm global modules directory.
nodeVersionNoInstalled Node.js version, if any.
opencodeBinNoPath to the opencode binary, if installed.
dockerRunningNoWhether the Docker daemon is reachable.
packageManagerNoDetected package manager (apt-get, dnf, yum, apk, pacman, zypper, or none).
workspaceDefaultYesDefault directory where the profile repo will be cloned.

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

A4.4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint, idempotentHint and openWorldHint, so the safety profile is partly covered. The description still adds real value beyond them: 'one shell probe, changes nothing', 'installs nothing', and the security-relevant detail that credentials are reported by name and never by value. It does not discuss failure modes when SSH is unreachable or probe cost/latency.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

A single dense paragraph that front-loads what is probed and what is returned, then moves to routing and safety. Every clause carries information, though the long output enumeration makes it slightly heavier than necessary given an output schema exists.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Output schema exists, so return values need not be explained, yet the description still names the key fields. Combined with explicit read-only/no-install guarantees, sibling routing, and full param coverage, an agent has everything needed to call this correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the nested target object and its mode/host/user/port/identityFile fields are already fully documented. The description only restates the local/ssh distinction already in the enum descriptions and adds no SSH syntax, default, or precedence detail beyond the schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb (probe) and resource (one Linux machine, local or SSH) and enumerates exactly what it reports: OS, kernel, architecture, package manager, Node/npm, OpenCode, Docker, per-tool flags, and credential names. This is precise enough to distinguish it from list_required_credentials and plan_clone without opening any schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly routes the agent: use it to see what a clone would touch, then plan_clone for an ordered plan, and bootstrap_host for first-time end-to-end provisioning. Both the when-to-use condition and the named alternatives are present.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.