Skip to main content
Glama

nsgoods-workbench-mcp

Verify signature

verify_signature
Read-onlyIdempotent

Offline EIP-191 verify of a signed nsgoods response. Identifies the service from the manifest (or the optional service arg), strips exactly that service's post-sign fields, canonicalises (JCS, both ASCII modes), recovers the signer and checks it against the published manifest signers. Reproduction-attestation (JCS/byte-length) and envelope (signer/signature, components) shapes are reported as unsupported_shape, not verified here. Refusals carry a distinct status: malformed_signature (signature is not a 65-byte 0x-prefixed hex string), schema_rejected (the body carries a signed_by/signature pair but fails the required field shape for every service the claimed signer covers; recovery was not attempted, checked is false, reasons lists the failed candidates), signature_mismatch (well-formed but recovers a different address than signed_by under every candidate service recipe of this signer), no_flat_recipe (signed_by is a manifest signer but every service it covers uses an envelope shape, so there is no flat recipe to check; recovery was not attempted, checked is false), unknown_signer (signed_by is not a manifest signer; recovery was not attempted, checked is false), unsupported_shape, or the no-signed_by/signature-pair case. checked is true only when EIP-191 recovery actually ran; every other refusal reports checked false.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
serviceNo
response_jsonYes

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed1 schema field changed
    • addedInput schema / properties / service
      Added value: +{
      +  "default": "",
      +  "title": "Service",
      +  "type": "string"
      +}
  2. First observed

TDQS

A4.5/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Despite annotations declaring readOnlyHint, openWorldHint, and idempotentHint, the description adds substantial behavioral detail: offline processing, canonicalisation, signer recovery, and the full catalog of refusal statuses with exact conditions for each. It even explains when 'checked' is true/false. This goes far beyond the annotations and sets accurate expectations.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is dense and long, but every sentence adds critical information about statuses and behavior. It is front-loaded with the core purpose and then expands into necessary edge cases. While a more structured list might improve readability, the substance justifies the length.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the description explains the result statuses and the 'checked' flag, which covers most of what an agent needs. It does not explicitly state what a successful verification response looks like (e.g., a status field with 'verified'), which is a minor gap, but the refusal cases are thoroughly documented.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 0%, so the description carries the burden. It explains `service` as an optional override ('or the optional `service` arg') and `response_json` as the signed nsgoods response. Both parameters are given meaningful context, though the exact format or constraints of response_json are not detailed.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description opens with 'Offline EIP-191 verify of a signed nsgoods response', a specific verb and resource that distinguishes this tool from all siblings. It clearly states what the tool does and its scope, leaving no ambiguity about its purpose.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description gives clear context: it handles signed nsgoods responses and can optionally take a service argument. It also explicitly states when it will not verify (unsupported_shape cases), though it does not name alternative tools because none appear to exist. This is clear contextual guidance with exclusions, just short of explicit 'use this instead of X' routing.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.