Validate a plugin blueprint
xpex_factory_validate_blueprintValidate a plugin blueprint and run XPeX security policy checks without generating or publishing anything.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| blueprint | Yes |
xpex_factory_validate_blueprintValidate a plugin blueprint and run XPeX security policy checks without generating or publishing anything.
| Name | Required | Description | Default |
|---|---|---|---|
| blueprint | Yes |
Changes observed during successful MCP inspections.
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint=true, idempotentHint=true, and destructiveHint=false, so the safety profile is covered structurally. The description adds that security policy checks are executed (useful context) but discloses nothing about validation output, failure modes, or how a valid vs invalid blueprint is reported.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
A single well-formed sentence that leads with the action and ends with the scoping constraint. Efficient and front-loaded, though brevity here may be a symptom of underspecification rather than discipline.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a tool whose sole input is an undocumented nested object and which has no output schema, the description should explain what a blueprint contains and what validation reports back. It leaves both gaps open, so an agent cannot confidently construct or interpret a call.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
There is one required parameter, 'blueprint', whose schema coverage is 0% and whose type is a nested object with no documented shape. The description merely restates the parameter name and adds no structural or content detail, so it fails to compensate for the coverage gap.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb and resource ('Validate a plugin blueprint') plus the scope of checks ('run XPeX security policy checks'). The 'without generating or publishing anything' clause implicitly distinguishes it from generation siblings like compile_plugin, but it never names a sibling outright.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The negative scope ('without generating or publishing anything') implies when this tool is preferred over preview_plugin/compile_plugin, but there is no explicit when-to-use statement or named alternative. Usage is left to inference.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Add one secure layer between your agents and this server.