ADT Security MCP Server
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@ADT Security MCP ServerIs my security system armed and are all the doors locked?"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
ADT Security MCP Server
Control and monitor an ADT Control / Alarm.com security system from any MCP-compatible host. This local stdio MCP server pairs structured, text-first tools with an interactive MCP App dashboard, so you can check system and device state, review recent activity, and safely arm, disarm, lock, or adjust devices, all backed by a two-step confirmation flow and a local, credential-free audit trail.
Developed by Anthony Cavanaugh for Cavanaugh Design Studio
Requirements
Node.js 22 or newer
An MCP host that supports stdio. MCP Apps support is optional because
open-standalone-dashboardprovides the same dashboard in a browser.Optional ADT Control credentials for real-device reads
Related MCP server: homeassistant-gateway
Install and verify
npm install
npm run verifyverify runs strict TypeScript checks, unit and in-memory MCP contract tests, a clean production build, and a process-level stdio/standalone negotiation test against the built artifact. Before publishing, use npm run release to add the production dependency audit and package-content dry run.
Configuration
Credentials are read only from the server process environment. They are never accepted as tool arguments or stored in the audit log.
Variable | Meaning |
| Set |
| ADT Control / Alarm.com account username. Must be set with |
| Account password. |
| Optional token supported by the upstream client. |
| Required when the account exposes more than one system. |
| Real accounts are read-only unless set to |
| Optional audit path. Default: |
| Optional loopback dashboard port. Default: an available ephemeral port on |
Partial real credentials fail closed. When multiple systems are available, the server refuses to guess.
Host configuration
Build first with npm run build, then configure the host with an absolute path:
{
"mcpServers": {
"adt-security": {
"command": "node",
"args": ["C:/absolute/path/adt-mcp-app/mcp-server/dist/main.js"],
"env": {
"ADT_DEMO_MODE": "true"
}
}
}
}For a real account, replace the demo flag with credentials but omit ADT_ALLOW_MUTATIONS initially. Confirm the dashboard selects the expected system and devices, then explicitly add "ADT_ALLOW_MUTATIONS": "true" if device control is desired. Restart the host after configuration changes.
Tools
Tool | Behavior |
| Reads live system/device state and local recent activity. |
| Validates a proposed mutation and returns a short-lived one-use token. |
| Controls an exact panel using a matching confirmation token. |
| Locks or unlocks an exact device using a matching token. |
| Turns a light on/off and optionally sets dimmer brightness. |
| Sets off, heat, cool, or auto mode with bounded Fahrenheit setpoints. |
| Derives and prioritizes current alerts from live device state; the dashboard presents these explicitly. |
| Reads the redacted local MCP action audit, not provider history; the dashboard uses this dedicated workflow. |
| Downloads a supported camera image server-side without exposing the signed provider URL. |
| Creates an expiring, interactive loopback dashboard URL for clients without MCP Apps or with constrained frames. |
Every mutation is a two-step operation: call prepare-security-action, show its exact summary to the user, then pass its one-use token to the matching mutation tool. Tokens expire after two minutes and cannot be reused or applied to a different action.
Security and operations
The transport is local stdio; stdout is reserved for JSON-RPC. Diagnostics use structured stderr.
The fullscreen control first requests native host fullscreen. If the host rejects it or stays inline, the app uses the standard host open-link request to open a separate browser dashboard.
Standalone dashboards bind only to
127.0.0.1. The URL contains a two-minute, one-use bootstrap token; the page exchanges it for a one-hour browser-only session, stores that session in tab-scoped storage, and removes the bootstrap token from the address bar.The standalone browser API exposes only dashboard refresh, action preparation/commit, and camera snapshots. It reuses the same validation, mutation policy, one-use confirmations, provider, and audit log as the MCP tools; ADT credentials remain server-side.
Browser mutations require an authenticated session, exact same-origin requests, JSON bodies capped at 16 KB, and the same visible two-step confirmation dialog used in the MCP App.
Real mutations are disabled by default.
A command whose transport fails or times out after dispatch returns
uncertainand disables all further device control for that server session. The upstream library cannot cancel it, so it may still complete. Inspect the operation in ADT and ensure no command remains pending before restarting; never restart solely to retry an uncertain command.Accepted commands whose verification read fails remain
submitted, with a warning, rather than being recorded as failed. Partial thermostat writes are treated as uncertain.Authentication uses a five-minute cache independent of the upstream library's missing expiry field. Concurrent logins are coalesced; expired authentication is refreshed once for reads. Physical writes are never retried automatically.
System state explicitly reports armed, disarmed, mixed, or unknown across every panel.
system.armedisnullfor mixed/unknown state. The dashboard displays controls for each panel.Audit entries contain action type, target ID, outcome, duration, and a safe error code. Credentials and confirmation tokens are excluded.
The audit file is created with restrictive permissions where supported and rotates at 5 MB to one backup.
Camera downloads are bounded to 5 MB and validated as image content.
Camera snapshot URLs must use credential-free HTTPS, resolve only to public addresses, pass the same validation after every redirect, and stream under a hard 5 MB limit.
Camera connections use the validated IP directly while retaining the original hostname for TLS certificate verification and the Host header. One download deadline covers DNS validation, redirects, connection, and body streaming.
The dashboard has no external connect, resource, frame, or base-URI domains in its declared CSP.
Fullscreen and VS Code
After rebuilding and restarting the MCP server, select the maximize control beside Refresh. A host that supports MCP fullscreen expands the app natively. If VS Code leaves it inline, the same control requests a protected standalone dashboard through the host's open-link capability.
If VS Code denies or does not implement open-link, the app displays a copyable http://127.0.0.1:.../mcp-app.html#token=... URL. Run Simple Browser: Show from the VS Code Command Palette and paste that URL within two minutes. Keep the MCP server process running; the exchanged browser session lasts one hour.
Clients that support MCP tools but not MCP Apps can call open-standalone-dashboard directly and present its returned URL. The standalone entrypoint provides the complete dashboard workflow, including confirmation-gated device controls and supported camera snapshots.
Scripts
npm run typecheck strict source and test checking
npm test source/unit/in-memory MCP tests
npm run build clean dashboard, server, and declaration build
npm run test:dist built stdio protocol smoke test
npm run verify all of the above
npm run audit:prod production dependency audit
npm run pack:check inspect the npm package contents without creating a tarball
npm run release verify, production audit, and package dry runKnown boundary
The integration relies on the unofficial node-alarm-dot-com library and private upstream behavior. It is not affiliated with ADT or Alarm.com, and upstream changes may break authentication or commands. Demo and protocol behavior are automated; release validation against a real account must be performed read-only first.
An uncertain command disables further writes only within the running server process; an upstream command may outlive a process restart. Reconcile it in ADT before restarting. A fresh browser link replaces an expired stored session; expired sessions are removed without automatically retrying actions.
Demo mode does not fabricate camera imagery. get-alerts reflects current state, and get-event-history is only this server's local action record.
📝 License
MIT License — see LICENSE for details.
Available Tools
11 toolsadt-dashboardADT Security DashboardBRead-onlyIdempotent
Read the current ADT security system and device state. Credentials come only from the server environment.
| Name | Required | Description | Default |
|---|---|---|---|
| action | No | view |
Output Schema
| Name | Required | Description |
|---|---|---|
| system | Yes | |
| devices | Yes | |
| refreshedAt | Yes | |
| recentActivity | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint/idempotentHint/destructiveHint=false, so the safety profile is covered. The description adds one genuinely useful non-schema fact: credentials are supplied only from the server environment, so no caller auth is needed. It says nothing, however, about what the 'refresh' action does behaviorally (poll, re-authenticate, latency), which is the main undisclosed behavior.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two short sentences, front-loaded with the purpose, and no filler. The credential sentence is relevant to invocation. Slightly lean for the information load, but nothing is wasted.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
An output schema exists, so return values need not be explained, and annotations cover the safety profile. Still, the description omits the action parameter's semantics and offers no sibling routing, which are the two gaps an agent calling this tool would trip on.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 0% and the single 'action' parameter is only an enum of view/refresh with a default. The description never mentions the action switch or explains the difference between viewing and refreshing, so it fails to compensate for the schema's total lack of parameter documentation.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb and resource: read the current ADT security system and device state. It is clear what the tool does, but it never distinguishes itself from the closely related sibling 'open-standalone-dashboard', leaving the agent to guess which of the two to pick for dashboard state.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
No when-to-use or when-not-to-use guidance is given, and none of the alternatives (get-alerts, get-event-history, get-camera-snapshot, open-standalone-dashboard) are referenced. 'Read the current... state' weakly implies a snapshot use case, but the agent gets no routing help.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
arm-systemArm ADT Security SystemADestructive
Arm one exact panel after prepare-security-action returned a matching confirmation token.
| Name | Required | Description | Default |
|---|---|---|---|
| mode | Yes | ||
| panelId | Yes | ||
| confirmationToken | Yes | One-use token returned by prepare-security-action |
Output Schema
| Name | Required | Description |
|---|---|---|
| status | Yes | |
| summary | Yes | |
| warning | No | |
| verifiedAt | No | |
| operationId | Yes | |
| auditRecorded | No |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare destructiveHint=true, readOnlyHint=false, and idempotentHint=false, so the safety profile is covered. The description adds real context beyond that: this is a gated second step of a two-phase flow requiring a matching token, and it targets exactly one panel, which signals precision and non-reversibility pressure.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
A single front-loaded sentence that puts the action first and the precondition second, with no redundant or filler text.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
An output schema exists, so return values need not be explained, and the description covers the key gating flow for this destructive mutation. The one omission is any mention of the mode parameter, which an agent must still derive from the enum.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is only 33%, with just confirmationToken documented in the schema. The description reinforces panelId ('one exact panel') and the token provenance, but never mentions the 'mode' parameter or its stay/away enum, so it only partially compensates for the coverage gap.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description gives a specific verb ('Arm') and resource ('panel') and even bounds the scope to 'one exact panel,' so the operation is unambiguous. It does not directly differentiate itself from the sibling disarm-system, leaving the Arm/Disarm contrast to be inferred from the wording rather than stated.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
It states a clear precondition for use: the action must follow prepare-security-action returning a matching confirmation token. That is solid sequencing guidance, but there is no explicit note about when not to arm or what mode selection implies.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
control-lightControl ADT LightA
Turn a light on or off, optionally setting dimmer brightness, after prepare-security-action returned a matching confirmation token.
| Name | Required | Description | Default |
|---|---|---|---|
| isOn | Yes | ||
| lightId | Yes | ||
| brightness | No | ||
| confirmationToken | Yes | One-use token returned by prepare-security-action |
Output Schema
| Name | Required | Description |
|---|---|---|
| status | Yes | |
| summary | Yes | |
| warning | No | |
| verifiedAt | No | |
| operationId | Yes | |
| auditRecorded | No |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare this is a non-read-only, non-idempotent, non-destructive, open-world operation. The description adds real behavioral context beyond them: the confirmation-token gating and that brightness is optional. It does not mention rate limits or failure/expiry behavior of the token, keeping it at 4.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
A single dense sentence that front-loads the core action and appends the prerequisite as a trailing clause. No filler or redundant restatement of the name.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With an output schema present, return values need not be described, and the description covers the operation and the gating prerequisite. The main gap is lightId semantics, which neither the description nor the schema explains.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is only 25% (just confirmationToken), so the description must carry more weight. It clarifies isOn (on/off) and that brightness is an optional dimmer value, but lightId and the brightness range semantics are left entirely to the bare schema.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb (turn on/off) and resource (light) plus the optional brightness scope, which cleanly separates it from siblings like control-lock and set-thermostat. An agent can identify the operation without opening the schema.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Explicitly names the prerequisite flow: it must be called after prepare-security-action returns a matching confirmation token, which routes the agent to the correct sibling first. It lacks an explicit when-not clause (e.g. what to do without a valid token), so it stops short of a 5.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
control-lockControl ADT Door LockADestructive
Lock or unlock one exact lock after prepare-security-action returned a matching confirmation token. Unlocking requires explicit user approval.
| Name | Required | Description | Default |
|---|---|---|---|
| action | Yes | ||
| lockId | Yes | ||
| confirmationToken | Yes | One-use token returned by prepare-security-action |
Output Schema
| Name | Required | Description |
|---|---|---|
| status | Yes | |
| summary | Yes | |
| warning | No | |
| verifiedAt | No | |
| operationId | Yes | |
| auditRecorded | No |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare destructive, non-idempotent, open-world behavior; the description adds context beyond that: the confirmation-token chaining and the requirement for explicit user approval before unlocking. It does not describe failure modes or what happens if the token is stale.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two tight sentences, front-loaded with the action, then the prerequisite, then the approval constraint. No filler.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Output schema exists, so return values need no explanation, and the mutation risk is covered by annotations plus the approval note. The remaining gap is how to obtain lockId and what happens on token mismatch.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is only 33% — only confirmationToken is documented in the schema. The description clarifies the token must match prepare-security-action and implies lockId identifies one exact lock, but gives no guidance for supplying lockId (discovery source, format) or for choosing between lock/unlock beyond the approval note.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb pair (lock/unlock) and scopes it to 'one exact lock', which separates it from the system-wide arm-system/disarm-system siblings. It does not explicitly name those siblings, so it stops short of full differentiation.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Explicitly gives the precondition (must follow prepare-security-action returning a matching confirmation token) and an approval gate for unlocking. An agent knows exactly when it is allowed to call this and what must precede it.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
disarm-systemDisarm ADT Security SystemADestructive
Disarm one exact panel after prepare-security-action returned a matching confirmation token. This reduces physical security and requires explicit user approval.
| Name | Required | Description | Default |
|---|---|---|---|
| panelId | Yes | ||
| confirmationToken | Yes | One-use token returned by prepare-security-action |
Output Schema
| Name | Required | Description |
|---|---|---|
| status | Yes | |
| summary | Yes | |
| warning | No | |
| verifiedAt | No | |
| operationId | Yes | |
| auditRecorded | No |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare destructiveHint=true, readOnlyHint=false, idempotentHint=false, and openWorldHint=true. The description adds value beyond those by warning that the action reduces physical security and requires explicit user approval, which is a real operational constraint an agent must honor.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two sentences, zero filler, with the prerequisite and the safety consequence front-loaded ahead of any elaboration. Every clause carries operative information.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
An output schema exists so return values need no explanation, and annotations carry the safety profile. For a destructive, non-idempotent action the description covers the trigger condition and the approval requirement well; only edge-case handling (invalid or expired token) is absent, which is minor here.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 50%: confirmationToken is documented in the schema, panelId is not. The description adds meaning by saying the panel must be exact and the token must match the one from prepare-security-action, but it does not explain panelId format or failure behavior for a stale/reused token beyond the schema's 'one-use' note.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb (disarm), an exact resource scope (one exact panel), and the gating prerequisite (a matching confirmation token from prepare-security-action). This clearly distinguishes it from the sibling arm-system without opening either schema.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Explicitly conditions use on prepare-security-action having returned a matching confirmation token, and states the explicit user approval requirement. It does not name a hard alternative (e.g., when to use arm-system instead), but the precondition and situational context are clear.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
get-alertsGet Current ADT AlertsARead-onlyIdempotent
Derive current actionable alerts from live device state, including triggered sensors, offline devices, and battery warnings. This is not provider event history.
| Name | Required | Description | Default |
|---|---|---|---|
| limit | No |
Output Schema
| Name | Required | Description |
|---|---|---|
| alerts | Yes | |
| refreshedAt | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint, idempotentHint, openWorldHint, and non-destructive behavior, so the safety profile is covered. The description adds that alerts are derived from live state rather than stored events, which is meaningful behavioral context about freshness. It stops short of stating whether results are cached or how stale they can be.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two short sentences, front-loaded with the core action and followed by the disambiguating exclusion. No filler or repetition of the title.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
An output schema exists, so return values need not be explained, and the annotations cover the read-only profile. The description is nearly complete for a read tool, with only the undocumented limit parameter leaving a small gap.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
There is one parameter (limit, with default 20, min 1, max 100) and schema description coverage is 0%, so the schema documents constraints but conveys no meaning. The description never mentions pagination or the limit parameter, leaving the agent without guidance on result sizing.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb+resource ('Derive current actionable alerts from live device state') and enumerates the alert categories (triggered sensors, offline devices, battery warnings). It also explicitly disambiguates from the similarly named sibling get-event-history.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The sentence 'This is not provider event history' explicitly routes the agent away from get-event-history, which is the most likely confusion. However, it does not state positive use conditions (e.g. when to prefer this over adt-dashboard or get-camera-snapshot), so guidance is clear but incomplete.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
get-camera-snapshotGet ADT Camera SnapshotARead-only
Fetch a current camera snapshot through the server. Signed provider URLs are never returned.
| Name | Required | Description | Default |
|---|---|---|---|
| cameraId | Yes |
Output Schema
| Name | Required | Description |
|---|---|---|
| bytes | Yes | |
| cameraId | Yes | |
| mimeType | Yes | |
| capturedAt | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The annotations already declare readOnlyHint=true, destructiveHint=false, openWorldHint=true, and idempotentHint=false, so the safety profile is covered. The description adds a useful behavioral caveat that signed provider URLs are never returned, but it does not discuss authentication, rate limits, caching, or other runtime behavior.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is two short, front-loaded sentences with no wasted wording. The core action is stated first, followed by an important return-behavior caveat, making it easy to parse quickly.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a simple read-only snapshot tool, the description covers the main action and a notable output constraint, while annotations supply the safety profile and an output schema exists for return values. The main gap is parameter semantics, but the tool remains understandable enough to invoke correctly.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 0%, and the description does not mention the single required parameter cameraId or its format, source, or constraints. The schema only provides type and length bounds, so the description fails to compensate for the missing parameter documentation.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states a specific verb and resource: fetching a current camera snapshot. This clearly distinguishes it from sibling tools such as adt-dashboard, get-alerts, and arm-system. An agent can identify the tool's core operation without needing to inspect the schema.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description gives no explicit when-to-use guidance, prerequisites, or alternatives. It implies a simple fetch operation from the name and description, but does not tell the agent when this tool is preferable to other camera- or event-related siblings.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
get-event-historyGet Local ADT Action HistoryARead-onlyIdempotent
Read the redacted local audit history of mutation attempts made through this MCP server. It is not Alarm.com provider history.
| Name | Required | Description | Default |
|---|---|---|---|
| limit | No |
Output Schema
| Name | Required | Description |
|---|---|---|
| events | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint, idempotentHint, destructiveHint=false and openWorldHint=false, so the safety profile is covered. The description adds non-obvious context the annotations cannot convey: the data is redacted, it is local to this MCP server, and it records only mutation attempts, not provider history.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two tight sentences, front-loaded with the core action and the scope qualifier. The second sentence, a disambiguation from provider history, earns its place; nothing is redundant.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Because an output schema exists, return values need not be described, and the annotations carry the read-only safety profile. For a single-parameter read tool, the description covers what is read and its scope; only the limit/pagination behavior is left unaddressed.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 0% and the single 'limit' parameter (default 50, min 1, max 100) is never mentioned in the description. The schema's default and bounds make the parameter largely self-explanatory, but the description does nothing to compensate for the missing parameter documentation as required at this coverage level.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb (read) and resource (redacted local audit history of mutation attempts through this MCP server), which is precise and scoped. It distinguishes itself from provider-side history (Alarm.com), though it does not directly differentiate from siblings like get-alerts.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Usage is implied by the scope statement (review local mutation-attempt audit records), and the 'not Alarm.com provider history' clause rules out a false alternative. However, there is no explicit when-to-use guidance relative to sibling tools such as get-alerts or adt-dashboard.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
open-standalone-dashboardOpen ADT Dashboard in BrowserARead-only
Create an expiring, loopback-only URL for the full interactive ADT dashboard. Use this when the MCP client cannot render MCP Apps or constrains the app inside a frame.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
Output Schema
| Name | Required | Description |
|---|---|---|
| url | Yes | |
| expiresAt | Yes | |
| sessionMode | Yes | |
| sessionDurationMinutes | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint=true, openWorldHint=false and destructiveHint=false, so the safety profile is covered. The description adds non-obvious behavior beyond that: the URL is expiring and loopback-only, which tells the agent about lifetime and reachability limits it could not infer from the schema.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two sentences, zero filler, with the output (the URL) front-loaded before the usage condition. Every clause carries information.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With an output schema present, return-value details are unnecessary, and the description covers what is produced and when to use it. It omits the actual expiration window and whether the URL is single-use, which would help an agent decide how quickly to hand it to a user, but the core is complete.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The tool takes zero parameters, so the standard baseline of 4 applies. There is no parameter surface for the description to clarify or omit.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb (Create) and resource (an expiring, loopback-only URL for the full interactive ADT dashboard), which is far more precise than the title alone. It does not name the sibling adt-dashboard tool explicitly, so the contrast with the embedded variant is implied rather than stated.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Gives a clear triggering condition: use it when the MCP client cannot render MCP Apps or constrains the app inside a frame. It stops short of naming the alternative tool to use when that condition is not met, so it is strong context without full when/when-not routing.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
prepare-security-actionPreview ADT Security ActionARead-only
Validate and preview one security-system mutation. Returns a short-lived, one-use token required by the matching mutation tool. Show the summary to the user before continuing.
| Name | Required | Description | Default |
|---|---|---|---|
| action | Yes |
Output Schema
| Name | Required | Description |
|---|---|---|
| token | Yes | |
| action | Yes | |
| summary | Yes | |
| expiresAt | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations declare readOnlyHint=true, destructiveHint=false, and idempotentHint=false; the description adds that the tool returns a short-lived, one-use token, which is critical behavioral context. It doesn't detail token expiry or error behavior, but the core non-mutating, token-producing nature is transparent.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Three sentences, front-loaded with the core action, then the return value, then the user-facing instruction. No redundant or filler content.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Output schema exists, so return values need not be explained. The description covers purpose, prerequisite, and token use; it's complete enough for an agent to call it, though it could mention that the action object must conform to one of the supported mutation shapes.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 0%, and the description only says 'one security-system mutation' without explaining the structure of the action object (types like arm/disarm/lock, required fields, or enums). The description fails to compensate for the lack of schema descriptions, leaving parameter meaning entirely to the structural schema.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb (validate/preview) and resource (security-system mutation) and distinguishes itself from the actual mutation siblings by noting it returns a token required by the matching mutation tool. Slightly less than perfect because it doesn't name the specific sibling tools (e.g., arm-system, control-lock).
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Explicitly instructs to show the summary to the user before continuing, and implies it must be called before the matching mutation tool. It doesn't spell out when-not-to-use scenarios, but the prerequisite is clear.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
set-thermostatSet ADT ThermostatA
Change thermostat mode and bounded Fahrenheit setpoints after prepare-security-action returned a matching confirmation token.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
Output Schema
| Name | Required | Description |
|---|---|---|
| status | Yes | |
| summary | Yes | |
| warning | No | |
| verifiedAt | No | |
| operationId | Yes | |
| auditRecorded | No |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations cover the safety profile (readOnlyHint=false, destructiveHint=false, idempotentHint=false, openWorldHint=true). The description adds genuinely new behavioral context: the call is gated on a one-use confirmation token from a prior tool, which explains the non-idempotent nature and implies token expiry/reuse failure modes.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
A single sentence that front-loads the action and appends the gating precondition. No filler, and every clause carries operative information.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With an output schema present and 100% schema description coverage, the description needn't explain returns or field formats. The critical missing piece an agent would want, exact confirmation-token acquisition flow, is at least pointed at via the named sibling tool.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, so baseline is 3, but the description adds value beyond the schema by specifying units (Fahrenheit) that the schema omits and characterizing the setpoints as bounded, aligning with the 45-95 ranges. It doesn't spell out the auto/heat/cool branch structure explicitly.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb (Change), resource (thermostat), and scope (mode and bounded Fahrenheit setpoints), and names the upstream sibling prepare-security-action that gates the call. It distinguishes the tool from generic siblings, though it doesn't contrast against other security actions beyond the token dependency.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Gives a clear precondition: it must be called only after prepare-security-action has returned a matching confirmation token. There is no explicit when-not or alternative-selection guidance, but the precondition is the dominant usage rule for this tool.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
11 tool updates
v1.1.0- First observed
adt-dashboard - First observed
arm-system - First observed
control-light - First observed
control-lock - First observed
disarm-system - First observed
get-alerts - First observed
get-camera-snapshot - First observed
get-event-history - First observed
open-standalone-dashboard - First observed
prepare-security-action - First observed
set-thermostat
TDQS
Scored across 11 tools
Each tool targets a clearly distinct resource or action: dashboard read, standalone URL creation, action preparation, arm, disarm, lock, light, thermostat, alerts, audit history, and camera snapshot. The descriptions differentiate similar-sounding tools like adt-dashboard and open-standalone-dashboard, and the prepare-security-action gating makes mutation tools unambiguous.
All names are kebab-case and mostly follow a verb_noun pattern (arm-system, control-lock, get-alerts, set-thermostat). Minor deviations include adt-dashboard (noun-only) and open-standalone-dashboard (extra adjective), but the overall convention is predictable.
11 tools are well-scoped for an ADT security server: they cover state reading, action preparation, and mutations across panels, locks, lights, and thermostat, plus alerts, history, and camera. No obvious redundancy or missing tool class.
Core security operations (arm/disarm, lock, light, thermostat, alerts, camera, state read) are covered, with a safe prepare-then-mutate workflow. Minor gaps include no explicit device list, user management, or provider event history beyond current alerts, but adt-dashboard and get-alerts provide reasonable workarounds.
Maintenance
Related MCP Connectors
An authenticated remote MCP server for user-owned devices and one-shot capability invocation.
MCP server for mandates, delegation, policy-gated execution, credential grants, and audit.
A paid remote MCP for hosted MCP server, built to return verdicts, receipts, usage logs, and audit-r
Related MCP Servers
- AlicenseAqualityAmaintenanceMCP server for SimpliSafe home security. Enables checking system status, sensors, events, arming/disarming, and controlling smart locks.10813 npmMIT
- AlicenseNot gradedqualityAmaintenanceEnables secure, auditable access to Home Assistant through MCP, with a read-only observer profile and an operator profile for controlled mutations.2MIT
- AlicenseNot gradedqualityBmaintenanceCentral MCP gateway for smart home automation, enabling agents to safely control Home Assistant and Node-RED with identity-based access, human confirmation for writes, and a WebUI for governance.1MIT
- AlicenseAqualityCmaintenanceMCP server for Hubitat Elevation hubs that controls devices via the Maker API, with optional gated access to undocumented admin routes, supporting device listing, command sending, virtual device and hub variable automation for Rule Machine, and hub management features.8MIT