Skip to main content
Glama

FlowSentry

Scan Workflow

scan_workflow

Scan one n8n workflow JSON export (string) and return the findings report.

Accepts the raw workflow object ({'nodes': [...], ...}) or the CLI export wrapper ({'name':..., 'workflow': {...}}). Max 512 KB.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
nameNouploaded-workflow
workflow_jsonYes

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
resultYes

Schema Changelog

Changes observed during successful MCP inspections. Dates show when Glama detected each change.

  1. First observed

TDQS

A3.6/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description is the sole behavioral disclosure. It usefully states the accepted payload shapes, the 512 KB maximum, and that a report is returned, but it does not explicitly address side effects, permissions, or error behavior. 'Scan' implies read-only, but that is not made explicit.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two compact sentences with no filler: the main action is front-loaded, and the input constraints follow immediately. Every sentence earns its place.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Return values are presumably covered by the output schema, so no return explanation is needed. The description covers the required input form, wrapper variants, and size limit; the only notable gap is the purpose of the optional name parameter. Overall, near-complete for the tool's moderate complexity.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 0%, so the description must compensate. It adds meaningful detail for workflow_json by explaining the two acceptable JSON shapes and the size limit. However, it does not explain the optional name parameter's role, leaving partial compensation.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific action ('Scan one n8n workflow JSON export') and a clear output ('return the findings report'), identifying the resource and deliverable. It does not explicitly contrast with the sibling list_rules, but the scanning verb and workflow target are specific enough to mostly differentiate it.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Provides concrete input guidance by describing accepted raw workflow objects and CLI export wrappers, plus a size cap. It does not say when to choose this tool over list_rules or any alternative, leaving that to the agent's inference.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

TDQS

A3.9/5.0
Disambiguation5/5

The two tools have completely distinct purposes: one lists security rules, the other scans a workflow. There is no overlap or ambiguity in their functions.

Naming Consistency5/5

Both tool names follow a consistent verb_noun pattern (list_rules, scan_workflow), which is clear and predictable.

Tool Count3/5

With only two tools, the server feels minimal for its domain. While the tools cover the core actions, the count is on the low end of typical scope, making it borderline.

Completeness4/5

The two tools provide a complete workflow for understanding rules and running scans. Minor gaps exist (e.g., no per-rule detail view), but agents can work around them using the list output.