Skip to main content
Glama

Recipes Cve Catalog Info

recipes_cve_catalog_info

Return the complete Medium/High/Critical CVE catalog scope, coverage, provenance, and counts.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault

No arguments

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault

No arguments

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

A3.7/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations the description carries the full burden, and it does disclose that the returned scope is limited to Medium/High/Critical severities and includes provenance. However, it says nothing about permissions, freshness guarantees, or response size/caching for what is evidently a static metadata endpoint; the low inherent risk of a zero-arg read keeps this from being worse.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

A single front-loaded sentence naming the verb, resource, and returned fields with zero filler. Nothing is padded and nothing unrelated is included.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

An output schema exists, so return values need not be explained, and the description still previews the four content areas (scope, coverage, provenance, counts). For a simple zero-param info tool the definition is essentially complete, missing only an explicit pointer to the sibling CVE tools.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The tool takes zero parameters, so per the baseline there is nothing for the description to disambiguate. The severity-scoping language adds context about the implicit filter the catalog applies, which is a small bonus over an empty schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb ('Return') plus the resource ('CVE catalog') and enumerates exactly what the payload contains: scope, coverage, provenance, and counts. The severity framing (Medium/High/Critical) further narrows the scope, making it distinguishable from recipes_cve_get and recipes_cve_search, though it never names those siblings.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Usage is implied rather than stated: 'catalog info' reads as a metadata/about call to be used alongside the per-CVE get and search tools, but the description gives no explicit when-to-use, when-not-to-use, or alternative tool names. An agent can infer the role but is not guided.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.