Skip to main content
Glama

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault

No arguments

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Server capabilities have not been inspected yet.

Tools

Functions exposed to the LLM to take actions

NameDescription
capture_packetsB

Capture live traffic and provide raw packet data as JSON for LLM analysis

get_summary_statsC

Capture live traffic and provide protocol hierarchy statistics for LLM analysis

get_conversationsC

Capture live traffic and provide TCP/UDP conversation statistics for LLM analysis

check_threatsC

Capture live traffic and check IPs against URLhaus blacklist

check_ip_threatsC

Check a given IP address against URLhaus blacklist for IOCs

analyze_pcapC

Analyze a PCAP file and provide general packet data as JSON for LLM analysis

extract_credentialsC

Extract potential credentials (HTTP Basic Auth, FTP, Telnet) from a PCAP file for LLM analysis

Prompts

Interactive templates invoked by user choice

NameDescription
capture_packets_prompt
summary_stats_prompt
conversations_prompt
check_threats_prompt
check_ip_threats_prompt
analyze_pcap_prompt
extract_credentials_prompt

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

B3.3/5.0

Scored across 7 tools

Disambiguation3/5

There is significant overlap between tools, particularly among those that capture live traffic (capture_packets, check_threats, get_conversations, get_summary_stats), which could cause confusion as they all involve live capture but serve slightly different analysis purposes. However, the descriptions help differentiate their specific outputs (e.g., raw packet data vs. threat checking vs. conversation statistics), preventing complete ambiguity.

Naming Consistency4/5

Tool names follow a consistent verb_noun pattern (e.g., analyze_pcap, capture_packets, check_ip_threats), with all using snake_case and clear action-object phrasing. The only minor deviation is 'check_threats' lacking a specific object like 'ip' compared to 'check_ip_threats', but overall naming is predictable and readable.

Tool Count5/5

With 7 tools, the count is well-scoped for a network analysis server, covering key areas like packet analysis, threat detection, and credential extraction. Each tool appears to serve a distinct function within the domain, avoiding bloat while providing comprehensive coverage for typical tasks.

Completeness4/5

The tool set covers core network analysis workflows, including packet capture, threat checking, credential extraction, and statistical analysis, with both live and file-based options. A minor gap is the lack of tools for modifying or filtering traffic, but agents can likely work around this for most analysis tasks, making the surface reasonably complete.

Maintenance

ActivityInactive
ResponsivenessUnresponsive