Skip to main content
Glama

Patronus Security

Get scan status and results

get_scan
Read-onlyIdempotent

Read a public scan job belonging to the authenticated account. Works with jobs submitted through REST or MCP. Poll running jobs with backoff; completed and failed are terminal.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
job_idYesPublic Patronus job ID returned by a scan submission.

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault

No arguments

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed2 schema fields changed
    • addedInput schema / properties / job_id / description
      Added value: +"Public Patronus job ID returned by a scan submission."
    • changedOutput schema / (root)
      Previous value: -nullNew value: +{
      +  "$schema": "https://json-schema.org/draft/2020-12/schema",
      +  "additionalProperties": {},
      +  "description": "Patronus scan response or public scan job envelope.",
      +  "propertyNames": {
      +    "type": "string"
      +  },
      +  "type": "object"
      +}
  2. First observed

TDQS

A4.5/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint=true, idempotentHint=true, and destructiveHint=false. The description adds meaningful behavioral context beyond that: the job must be public and belong to the authenticated account, it supports jobs from REST or MCP, and it explains polling semantics with terminal states. No contradictions.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two sentences, both earning their place: the first states purpose and scope, the second gives operational guidance. No filler or repetition of schema/annotation details.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a single-parameter read tool with a rich output schema and thorough annotations, the description is complete. It covers authentication scope, compatibility, polling behavior, and terminal states—everything an agent needs to invoke and use the tool correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100% and the job_id parameter already has a clear description ('Public Patronus job ID returned by a scan submission'). The tool description adds no additional parameter semantics, so the baseline score of 3 for full schema coverage applies.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a specific verb and resource: 'Read a public scan job belonging to the authenticated account.' This clearly distinguishes it from sibling tools like scan_file, scan_text, and submit_scan, which are about creating or submitting scans rather than retrieving status/results.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description gives clear contextual guidance: it works with jobs from REST or MCP, and advises polling running jobs with backoff while noting that completed and failed are terminal. It does not explicitly name alternatives or state when not to use it, but the sibling tool set makes the intended use obvious.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources