Skip to main content
Glama

Physical Capability Cloud

pcc_trilobio_validate_script

Quick lint of a tcode-api Python script before submission to a Trilobio fleet controller. Wraps validateTcodeScript() from @pcc/trilobio. Surface check only — NOT a sandbox or sanitizer. Looks for: imports of tcode_api (presence required), obviously dangerous statements (subprocess, os.system, eval, exec, import, socket, urllib, requests, file writes), empty scripts, and missing top-level tcode commands. Returns { valid: boolean, errors: string[], warnings?: string[] }. Operators with allowArbitraryScripts=true should treat results as a hint — the fleet controller is the source of truth on safety. Note: TypeScript package helper (no HTTP call); for programmatic use, import { validateTcodeScript } from "@pcc/trilobio".

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
sourceYesFull Python source of the tcode-api script to lint

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

A4.3/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Adds substantial context beyond annotations: the exact classes of issues checked, that it makes no HTTP call, the return shape, and its authority limits versus the fleet controller. Minor tension with readOnlyHint=false given it claims to be a pure helper with no side effects, though this is likely the default annotation rather than a true contradiction.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Dense but fully front-loaded: purpose first, then scope limits, checks performed, return shape, and caveats. Every sentence carries actionable information with no filler.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the description inlines the return shape ({ valid, errors, warnings? }), explains the safety authority model, and covers the lint's limitations. An agent has everything needed to call and interpret it correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Single parameter with 100% schema description coverage, so the schema already documents 'source'. The description implies the input is full Python source but adds no format or syntax detail beyond what the schema provides, so the baseline of 3 applies.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb (lint/validate) and resource (tcode-api Python script) and its purpose (pre-submission check for a Trilobio fleet controller). It also names what it wraps and clarifies it is a TypeScript package helper, distinguishing it cleanly from pcc_trilobio_build_config, pcc_trilobio_capability_template, and pcc_trilobio_validate_options.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly frames the use case (before submission to the fleet controller) and sets boundaries ('Surface check only — NOT a sandbox or sanitizer'; results are a hint when allowArbitraryScripts=true). It does not name sibling alternatives directly, but the context is unambiguous.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.