Skip to main content
Glama

TestChimp

report-dast-findings

Upload a ZAP Traditional JSON report for a security scan. Pass --id and --report-file . Backend parses alerts, dedupes by bug hash, and inserts new SECURITY bugs linked to the scan. Does not mark the scan COMPLETED — the DAST playbook calls update-scan-progress COMPLETED after this.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
idYes
reportFileYes

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

A4.2/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations the description carries the full burden, and it delivers: it discloses parsing, dedupe by bug hash, insertion of new SECURITY bugs linked to the scan, and the critical caveat that the scan is not marked COMPLETED. It omits auth/permission needs and error or overwrite behavior.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Four tight sentences, front-loaded with the action and the input, then behavior, then the sequencing caveat. Nothing is redundant.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Covers purpose, inputs, side effects, and the handoff to update-scan-progress for a mutation tool with no annotations and no output schema. The only real gap is that with no output schema it never hints at what the call returns (e.g. count of inserted bugs).

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 0%, so the description must compensate, and it partially does by implying id is the scan and reportFile is a path to a ZAP Traditional JSON report. However it uses CLI flag names (--id, --report-file) that do not match the schema property names (id, reportFile), and gives no format/constraint detail.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

Names a specific verb (upload), resource (ZAP Traditional JSON report) and the domain (security scan), which cleanly separates it from the sibling report-sast-findings/report-secrets-findings/report-deps-findings. It also states the downstream effect on SECURITY bugs and scan status.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly states it does NOT complete the scan and names update-scan-progress COMPLETED as the follow-up call, which is strong sequencing guidance. It does not explicitly say when to pick this over the SAST/secrets/deps siblings, but the ZAP/DAST framing makes the selection obvious.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.