Skip to main content
Glama
Cavanaugh-Design-Studio

ADT Security MCP Server

ADT Security MCP Server

Control and monitor an ADT Control / Alarm.com security system from any MCP-compatible host. This local stdio MCP server pairs structured, text-first tools with an interactive MCP App dashboard, so you can check system and device state, review recent activity, and safely arm, disarm, lock, or adjust devices, all backed by a two-step confirmation flow and a local, credential-free audit trail.

Developed by Anthony Cavanaugh for Cavanaugh Design Studio

Requirements

  • Node.js 22 or newer

  • An MCP host that supports stdio. MCP Apps support is optional because open-standalone-dashboard provides the same dashboard in a browser.

  • Optional ADT Control credentials for real-device reads

Related MCP server: homeassistant-gateway

Install and verify

npm install
npm run verify

verify runs strict TypeScript checks, unit and in-memory MCP contract tests, a clean production build, and a process-level stdio/standalone negotiation test against the built artifact. Before publishing, use npm run release to add the production dependency audit and package-content dry run.

Configuration

Credentials are read only from the server process environment. They are never accepted as tool arguments or stored in the audit log.

Variable

Meaning

ADT_DEMO_MODE

Set true to force the stateful demo provider. Demo is also selected when no username/password are configured.

ADT_USERNAME

ADT Control / Alarm.com account username. Must be set with ADT_PASSWORD.

ADT_PASSWORD

Account password.

ADT_MFA_TOKEN

Optional token supported by the upstream client.

ADT_SYSTEM_ID

Required when the account exposes more than one system.

ADT_ALLOW_MUTATIONS

Real accounts are read-only unless set to true.

ADT_AUDIT_LOG_PATH

Optional audit path. Default: ~/.adt-mcp/audit.jsonl.

ADT_STANDALONE_PORT

Optional loopback dashboard port. Default: an available ephemeral port on 127.0.0.1.

Partial real credentials fail closed. When multiple systems are available, the server refuses to guess.

Host configuration

Build first with npm run build, then configure the host with an absolute path:

{
  "mcpServers": {
    "adt-security": {
      "command": "node",
      "args": ["C:/absolute/path/adt-mcp-app/mcp-server/dist/main.js"],
      "env": {
        "ADT_DEMO_MODE": "true"
      }
    }
  }
}

For a real account, replace the demo flag with credentials but omit ADT_ALLOW_MUTATIONS initially. Confirm the dashboard selects the expected system and devices, then explicitly add "ADT_ALLOW_MUTATIONS": "true" if device control is desired. Restart the host after configuration changes.

Tools

Tool

Behavior

adt-dashboard

Reads live system/device state and local recent activity.

prepare-security-action

Validates a proposed mutation and returns a short-lived one-use token.

arm-system / disarm-system

Controls an exact panel using a matching confirmation token.

control-lock

Locks or unlocks an exact device using a matching token.

control-light

Turns a light on/off and optionally sets dimmer brightness.

set-thermostat

Sets off, heat, cool, or auto mode with bounded Fahrenheit setpoints.

get-alerts

Derives and prioritizes current alerts from live device state; the dashboard presents these explicitly.

get-event-history

Reads the redacted local MCP action audit, not provider history; the dashboard uses this dedicated workflow.

get-camera-snapshot

Downloads a supported camera image server-side without exposing the signed provider URL.

open-standalone-dashboard

Creates an expiring, interactive loopback dashboard URL for clients without MCP Apps or with constrained frames.

Every mutation is a two-step operation: call prepare-security-action, show its exact summary to the user, then pass its one-use token to the matching mutation tool. Tokens expire after two minutes and cannot be reused or applied to a different action.

Security and operations

  • The transport is local stdio; stdout is reserved for JSON-RPC. Diagnostics use structured stderr.

  • The fullscreen control first requests native host fullscreen. If the host rejects it or stays inline, the app uses the standard host open-link request to open a separate browser dashboard.

  • Standalone dashboards bind only to 127.0.0.1. The URL contains a two-minute, one-use bootstrap token; the page exchanges it for a one-hour browser-only session, stores that session in tab-scoped storage, and removes the bootstrap token from the address bar.

  • The standalone browser API exposes only dashboard refresh, action preparation/commit, and camera snapshots. It reuses the same validation, mutation policy, one-use confirmations, provider, and audit log as the MCP tools; ADT credentials remain server-side.

  • Browser mutations require an authenticated session, exact same-origin requests, JSON bodies capped at 16 KB, and the same visible two-step confirmation dialog used in the MCP App.

  • Real mutations are disabled by default.

  • A command whose transport fails or times out after dispatch returns uncertain and disables all further device control for that server session. The upstream library cannot cancel it, so it may still complete. Inspect the operation in ADT and ensure no command remains pending before restarting; never restart solely to retry an uncertain command.

  • Accepted commands whose verification read fails remain submitted, with a warning, rather than being recorded as failed. Partial thermostat writes are treated as uncertain.

  • Authentication uses a five-minute cache independent of the upstream library's missing expiry field. Concurrent logins are coalesced; expired authentication is refreshed once for reads. Physical writes are never retried automatically.

  • System state explicitly reports armed, disarmed, mixed, or unknown across every panel. system.armed is null for mixed/unknown state. The dashboard displays controls for each panel.

  • Audit entries contain action type, target ID, outcome, duration, and a safe error code. Credentials and confirmation tokens are excluded.

  • The audit file is created with restrictive permissions where supported and rotates at 5 MB to one backup.

  • Camera downloads are bounded to 5 MB and validated as image content.

  • Camera snapshot URLs must use credential-free HTTPS, resolve only to public addresses, pass the same validation after every redirect, and stream under a hard 5 MB limit.

  • Camera connections use the validated IP directly while retaining the original hostname for TLS certificate verification and the Host header. One download deadline covers DNS validation, redirects, connection, and body streaming.

  • The dashboard has no external connect, resource, frame, or base-URI domains in its declared CSP.

Fullscreen and VS Code

After rebuilding and restarting the MCP server, select the maximize control beside Refresh. A host that supports MCP fullscreen expands the app natively. If VS Code leaves it inline, the same control requests a protected standalone dashboard through the host's open-link capability.

If VS Code denies or does not implement open-link, the app displays a copyable http://127.0.0.1:.../mcp-app.html#token=... URL. Run Simple Browser: Show from the VS Code Command Palette and paste that URL within two minutes. Keep the MCP server process running; the exchanged browser session lasts one hour.

Clients that support MCP tools but not MCP Apps can call open-standalone-dashboard directly and present its returned URL. The standalone entrypoint provides the complete dashboard workflow, including confirmation-gated device controls and supported camera snapshots.

Scripts

npm run typecheck   strict source and test checking
npm test            source/unit/in-memory MCP tests
npm run build       clean dashboard, server, and declaration build
npm run test:dist   built stdio protocol smoke test
npm run verify      all of the above
npm run audit:prod  production dependency audit
npm run pack:check  inspect the npm package contents without creating a tarball
npm run release     verify, production audit, and package dry run

Known boundary

The integration relies on the unofficial node-alarm-dot-com library and private upstream behavior. It is not affiliated with ADT or Alarm.com, and upstream changes may break authentication or commands. Demo and protocol behavior are automated; release validation against a real account must be performed read-only first.

An uncertain command disables further writes only within the running server process; an upstream command may outlive a process restart. Reconcile it in ADT before restarting. A fresh browser link replaces an expired stored session; expired sessions are removed without automatically retrying actions.

Demo mode does not fabricate camera imagery. get-alerts reflects current state, and get-event-history is only this server's local action record.

📝 License

MIT License — see LICENSE for details.

Available Tools

11 tools
adt-dashboardADT Security DashboardB
Read-onlyIdempotent

Read the current ADT security system and device state. Credentials come only from the server environment.

ParametersJSON Schema
NameRequiredDescriptionDefault
actionNoview

Output Schema

ParametersJSON Schema
NameRequiredDescription
systemYes
devicesYes
refreshedAtYes
recentActivityYes

TDQS

B3/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint/idempotentHint/destructiveHint=false, so the safety profile is covered. The description adds one genuinely useful non-schema fact: credentials are supplied only from the server environment, so no caller auth is needed. It says nothing, however, about what the 'refresh' action does behaviorally (poll, re-authenticate, latency), which is the main undisclosed behavior.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two short sentences, front-loaded with the purpose, and no filler. The credential sentence is relevant to invocation. Slightly lean for the information load, but nothing is wasted.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

An output schema exists, so return values need not be explained, and annotations cover the safety profile. Still, the description omits the action parameter's semantics and offers no sibling routing, which are the two gaps an agent calling this tool would trip on.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters2/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 0% and the single 'action' parameter is only an enum of view/refresh with a default. The description never mentions the action switch or explains the difference between viewing and refreshing, so it fails to compensate for the schema's total lack of parameter documentation.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource: read the current ADT security system and device state. It is clear what the tool does, but it never distinguishes itself from the closely related sibling 'open-standalone-dashboard', leaving the agent to guess which of the two to pick for dashboard state.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

No when-to-use or when-not-to-use guidance is given, and none of the alternatives (get-alerts, get-event-history, get-camera-snapshot, open-standalone-dashboard) are referenced. 'Read the current... state' weakly implies a snapshot use case, but the agent gets no routing help.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

arm-systemArm ADT Security SystemA
Destructive

Arm one exact panel after prepare-security-action returned a matching confirmation token.

ParametersJSON Schema
NameRequiredDescriptionDefault
modeYes
panelIdYes
confirmationTokenYesOne-use token returned by prepare-security-action

Output Schema

ParametersJSON Schema
NameRequiredDescription
statusYes
summaryYes
warningNo
verifiedAtNo
operationIdYes
auditRecordedNo

TDQS

A4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare destructiveHint=true, readOnlyHint=false, and idempotentHint=false, so the safety profile is covered. The description adds real context beyond that: this is a gated second step of a two-phase flow requiring a matching token, and it targets exactly one panel, which signals precision and non-reversibility pressure.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

A single front-loaded sentence that puts the action first and the precondition second, with no redundant or filler text.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

An output schema exists, so return values need not be explained, and the description covers the key gating flow for this destructive mutation. The one omission is any mention of the mode parameter, which an agent must still derive from the enum.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is only 33%, with just confirmationToken documented in the schema. The description reinforces panelId ('one exact panel') and the token provenance, but never mentions the 'mode' parameter or its stay/away enum, so it only partially compensates for the coverage gap.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description gives a specific verb ('Arm') and resource ('panel') and even bounds the scope to 'one exact panel,' so the operation is unambiguous. It does not directly differentiate itself from the sibling disarm-system, leaving the Arm/Disarm contrast to be inferred from the wording rather than stated.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It states a clear precondition for use: the action must follow prepare-security-action returning a matching confirmation token. That is solid sequencing guidance, but there is no explicit note about when not to arm or what mode selection implies.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

control-lightControl ADT LightA

Turn a light on or off, optionally setting dimmer brightness, after prepare-security-action returned a matching confirmation token.

ParametersJSON Schema
NameRequiredDescriptionDefault
isOnYes
lightIdYes
brightnessNo
confirmationTokenYesOne-use token returned by prepare-security-action

Output Schema

ParametersJSON Schema
NameRequiredDescription
statusYes
summaryYes
warningNo
verifiedAtNo
operationIdYes
auditRecordedNo

TDQS

A4.2/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare this is a non-read-only, non-idempotent, non-destructive, open-world operation. The description adds real behavioral context beyond them: the confirmation-token gating and that brightness is optional. It does not mention rate limits or failure/expiry behavior of the token, keeping it at 4.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

A single dense sentence that front-loads the core action and appends the prerequisite as a trailing clause. No filler or redundant restatement of the name.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With an output schema present, return values need not be described, and the description covers the operation and the gating prerequisite. The main gap is lightId semantics, which neither the description nor the schema explains.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is only 25% (just confirmationToken), so the description must carry more weight. It clarifies isOn (on/off) and that brightness is an optional dimmer value, but lightId and the brightness range semantics are left entirely to the bare schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb (turn on/off) and resource (light) plus the optional brightness scope, which cleanly separates it from siblings like control-lock and set-thermostat. An agent can identify the operation without opening the schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly names the prerequisite flow: it must be called after prepare-security-action returns a matching confirmation token, which routes the agent to the correct sibling first. It lacks an explicit when-not clause (e.g. what to do without a valid token), so it stops short of a 5.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

control-lockControl ADT Door LockA
Destructive

Lock or unlock one exact lock after prepare-security-action returned a matching confirmation token. Unlocking requires explicit user approval.

ParametersJSON Schema
NameRequiredDescriptionDefault
actionYes
lockIdYes
confirmationTokenYesOne-use token returned by prepare-security-action

Output Schema

ParametersJSON Schema
NameRequiredDescription
statusYes
summaryYes
warningNo
verifiedAtNo
operationIdYes
auditRecordedNo

TDQS

A4.2/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare destructive, non-idempotent, open-world behavior; the description adds context beyond that: the confirmation-token chaining and the requirement for explicit user approval before unlocking. It does not describe failure modes or what happens if the token is stale.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two tight sentences, front-loaded with the action, then the prerequisite, then the approval constraint. No filler.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Output schema exists, so return values need no explanation, and the mutation risk is covered by annotations plus the approval note. The remaining gap is how to obtain lockId and what happens on token mismatch.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is only 33% — only confirmationToken is documented in the schema. The description clarifies the token must match prepare-security-action and implies lockId identifies one exact lock, but gives no guidance for supplying lockId (discovery source, format) or for choosing between lock/unlock beyond the approval note.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb pair (lock/unlock) and scopes it to 'one exact lock', which separates it from the system-wide arm-system/disarm-system siblings. It does not explicitly name those siblings, so it stops short of full differentiation.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly gives the precondition (must follow prepare-security-action returning a matching confirmation token) and an approval gate for unlocking. An agent knows exactly when it is allowed to call this and what must precede it.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

disarm-systemDisarm ADT Security SystemA
Destructive

Disarm one exact panel after prepare-security-action returned a matching confirmation token. This reduces physical security and requires explicit user approval.

ParametersJSON Schema
NameRequiredDescriptionDefault
panelIdYes
confirmationTokenYesOne-use token returned by prepare-security-action

Output Schema

ParametersJSON Schema
NameRequiredDescription
statusYes
summaryYes
warningNo
verifiedAtNo
operationIdYes
auditRecordedNo

TDQS

A4.2/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare destructiveHint=true, readOnlyHint=false, idempotentHint=false, and openWorldHint=true. The description adds value beyond those by warning that the action reduces physical security and requires explicit user approval, which is a real operational constraint an agent must honor.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two sentences, zero filler, with the prerequisite and the safety consequence front-loaded ahead of any elaboration. Every clause carries operative information.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

An output schema exists so return values need no explanation, and annotations carry the safety profile. For a destructive, non-idempotent action the description covers the trigger condition and the approval requirement well; only edge-case handling (invalid or expired token) is absent, which is minor here.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 50%: confirmationToken is documented in the schema, panelId is not. The description adds meaning by saying the panel must be exact and the token must match the one from prepare-security-action, but it does not explain panelId format or failure behavior for a stale/reused token beyond the schema's 'one-use' note.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb (disarm), an exact resource scope (one exact panel), and the gating prerequisite (a matching confirmation token from prepare-security-action). This clearly distinguishes it from the sibling arm-system without opening either schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly conditions use on prepare-security-action having returned a matching confirmation token, and states the explicit user approval requirement. It does not name a hard alternative (e.g., when to use arm-system instead), but the precondition and situational context are clear.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

get-alertsGet Current ADT AlertsA
Read-onlyIdempotent

Derive current actionable alerts from live device state, including triggered sensors, offline devices, and battery warnings. This is not provider event history.

ParametersJSON Schema
NameRequiredDescriptionDefault
limitNo

Output Schema

ParametersJSON Schema
NameRequiredDescription
alertsYes
refreshedAtYes

TDQS

A4.1/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint, idempotentHint, openWorldHint, and non-destructive behavior, so the safety profile is covered. The description adds that alerts are derived from live state rather than stored events, which is meaningful behavioral context about freshness. It stops short of stating whether results are cached or how stale they can be.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two short sentences, front-loaded with the core action and followed by the disambiguating exclusion. No filler or repetition of the title.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

An output schema exists, so return values need not be explained, and the annotations cover the read-only profile. The description is nearly complete for a read tool, with only the undocumented limit parameter leaving a small gap.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters2/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

There is one parameter (limit, with default 20, min 1, max 100) and schema description coverage is 0%, so the schema documents constraints but conveys no meaning. The description never mentions pagination or the limit parameter, leaving the agent without guidance on result sizing.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb+resource ('Derive current actionable alerts from live device state') and enumerates the alert categories (triggered sensors, offline devices, battery warnings). It also explicitly disambiguates from the similarly named sibling get-event-history.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The sentence 'This is not provider event history' explicitly routes the agent away from get-event-history, which is the most likely confusion. However, it does not state positive use conditions (e.g. when to prefer this over adt-dashboard or get-camera-snapshot), so guidance is clear but incomplete.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

get-camera-snapshotGet ADT Camera SnapshotA
Read-only

Fetch a current camera snapshot through the server. Signed provider URLs are never returned.

ParametersJSON Schema
NameRequiredDescriptionDefault
cameraIdYes

Output Schema

ParametersJSON Schema
NameRequiredDescription
bytesYes
cameraIdYes
mimeTypeYes
capturedAtYes

TDQS

A3.5/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

The annotations already declare readOnlyHint=true, destructiveHint=false, openWorldHint=true, and idempotentHint=false, so the safety profile is covered. The description adds a useful behavioral caveat that signed provider URLs are never returned, but it does not discuss authentication, rate limits, caching, or other runtime behavior.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is two short, front-loaded sentences with no wasted wording. The core action is stated first, followed by an important return-behavior caveat, making it easy to parse quickly.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a simple read-only snapshot tool, the description covers the main action and a notable output constraint, while annotations supply the safety profile and an output schema exists for return values. The main gap is parameter semantics, but the tool remains understandable enough to invoke correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters2/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 0%, and the description does not mention the single required parameter cameraId or its format, source, or constraints. The schema only provides type and length bounds, so the description fails to compensate for the missing parameter documentation.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a specific verb and resource: fetching a current camera snapshot. This clearly distinguishes it from sibling tools such as adt-dashboard, get-alerts, and arm-system. An agent can identify the tool's core operation without needing to inspect the schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description gives no explicit when-to-use guidance, prerequisites, or alternatives. It implies a simple fetch operation from the name and description, but does not tell the agent when this tool is preferable to other camera- or event-related siblings.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

get-event-historyGet Local ADT Action HistoryA
Read-onlyIdempotent

Read the redacted local audit history of mutation attempts made through this MCP server. It is not Alarm.com provider history.

ParametersJSON Schema
NameRequiredDescriptionDefault
limitNo

Output Schema

ParametersJSON Schema
NameRequiredDescription
eventsYes

TDQS

A3.5/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint, idempotentHint, destructiveHint=false and openWorldHint=false, so the safety profile is covered. The description adds non-obvious context the annotations cannot convey: the data is redacted, it is local to this MCP server, and it records only mutation attempts, not provider history.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two tight sentences, front-loaded with the core action and the scope qualifier. The second sentence, a disambiguation from provider history, earns its place; nothing is redundant.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Because an output schema exists, return values need not be described, and the annotations carry the read-only safety profile. For a single-parameter read tool, the description covers what is read and its scope; only the limit/pagination behavior is left unaddressed.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters2/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 0% and the single 'limit' parameter (default 50, min 1, max 100) is never mentioned in the description. The schema's default and bounds make the parameter largely self-explanatory, but the description does nothing to compensate for the missing parameter documentation as required at this coverage level.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb (read) and resource (redacted local audit history of mutation attempts through this MCP server), which is precise and scoped. It distinguishes itself from provider-side history (Alarm.com), though it does not directly differentiate from siblings like get-alerts.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Usage is implied by the scope statement (review local mutation-attempt audit records), and the 'not Alarm.com provider history' clause rules out a false alternative. However, there is no explicit when-to-use guidance relative to sibling tools such as get-alerts or adt-dashboard.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

open-standalone-dashboardOpen ADT Dashboard in BrowserA
Read-only

Create an expiring, loopback-only URL for the full interactive ADT dashboard. Use this when the MCP client cannot render MCP Apps or constrains the app inside a frame.

ParametersJSON Schema
NameRequiredDescriptionDefault

No parameters

Output Schema

ParametersJSON Schema
NameRequiredDescription
urlYes
expiresAtYes
sessionModeYes
sessionDurationMinutesYes

TDQS

A4.1/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint=true, openWorldHint=false and destructiveHint=false, so the safety profile is covered. The description adds non-obvious behavior beyond that: the URL is expiring and loopback-only, which tells the agent about lifetime and reachability limits it could not infer from the schema.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two sentences, zero filler, with the output (the URL) front-loaded before the usage condition. Every clause carries information.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With an output schema present, return-value details are unnecessary, and the description covers what is produced and when to use it. It omits the actual expiration window and whether the URL is single-use, which would help an agent decide how quickly to hand it to a user, but the core is complete.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The tool takes zero parameters, so the standard baseline of 4 applies. There is no parameter surface for the description to clarify or omit.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb (Create) and resource (an expiring, loopback-only URL for the full interactive ADT dashboard), which is far more precise than the title alone. It does not name the sibling adt-dashboard tool explicitly, so the contrast with the embedded variant is implied rather than stated.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives a clear triggering condition: use it when the MCP client cannot render MCP Apps or constrains the app inside a frame. It stops short of naming the alternative tool to use when that condition is not met, so it is strong context without full when/when-not routing.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

prepare-security-actionPreview ADT Security ActionA
Read-only

Validate and preview one security-system mutation. Returns a short-lived, one-use token required by the matching mutation tool. Show the summary to the user before continuing.

ParametersJSON Schema
NameRequiredDescriptionDefault
actionYes

Output Schema

ParametersJSON Schema
NameRequiredDescription
tokenYes
actionYes
summaryYes
expiresAtYes

TDQS

A3.8/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations declare readOnlyHint=true, destructiveHint=false, and idempotentHint=false; the description adds that the tool returns a short-lived, one-use token, which is critical behavioral context. It doesn't detail token expiry or error behavior, but the core non-mutating, token-producing nature is transparent.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Three sentences, front-loaded with the core action, then the return value, then the user-facing instruction. No redundant or filler content.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Output schema exists, so return values need not be explained. The description covers purpose, prerequisite, and token use; it's complete enough for an agent to call it, though it could mention that the action object must conform to one of the supported mutation shapes.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters2/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 0%, and the description only says 'one security-system mutation' without explaining the structure of the action object (types like arm/disarm/lock, required fields, or enums). The description fails to compensate for the lack of schema descriptions, leaving parameter meaning entirely to the structural schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb (validate/preview) and resource (security-system mutation) and distinguishes itself from the actual mutation siblings by noting it returns a token required by the matching mutation tool. Slightly less than perfect because it doesn't name the specific sibling tools (e.g., arm-system, control-lock).

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly instructs to show the summary to the user before continuing, and implies it must be called before the matching mutation tool. It doesn't spell out when-not-to-use scenarios, but the prerequisite is clear.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

set-thermostatSet ADT ThermostatA

Change thermostat mode and bounded Fahrenheit setpoints after prepare-security-action returned a matching confirmation token.

ParametersJSON Schema
NameRequiredDescriptionDefault

No parameters

Output Schema

ParametersJSON Schema
NameRequiredDescription
statusYes
summaryYes
warningNo
verifiedAtNo
operationIdYes
auditRecordedNo

TDQS

A4.1/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations cover the safety profile (readOnlyHint=false, destructiveHint=false, idempotentHint=false, openWorldHint=true). The description adds genuinely new behavioral context: the call is gated on a one-use confirmation token from a prior tool, which explains the non-idempotent nature and implies token expiry/reuse failure modes.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

A single sentence that front-loads the action and appends the gating precondition. No filler, and every clause carries operative information.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With an output schema present and 100% schema description coverage, the description needn't explain returns or field formats. The critical missing piece an agent would want, exact confirmation-token acquisition flow, is at least pointed at via the named sibling tool.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so baseline is 3, but the description adds value beyond the schema by specifying units (Fahrenheit) that the schema omits and characterizing the setpoints as bounded, aligning with the 45-95 ranges. It doesn't spell out the auto/heat/cool branch structure explicitly.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb (Change), resource (thermostat), and scope (mode and bounded Fahrenheit setpoints), and names the upstream sibling prepare-security-action that gates the call. It distinguishes the tool from generic siblings, though it doesn't contrast against other security actions beyond the token dependency.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives a clear precondition: it must be called only after prepare-security-action has returned a matching confirmation token. There is no explicit when-not or alternative-selection guidance, but the precondition is the dominant usage rule for this tool.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections.

  1. 11 tool updatesv1.1.0
    • First observedadt-dashboard
    • First observedarm-system
    • First observedcontrol-light
    • First observedcontrol-lock
    • First observeddisarm-system
    • First observedget-alerts
    • First observedget-camera-snapshot
    • First observedget-event-history
    • First observedopen-standalone-dashboard
    • First observedprepare-security-action
    • First observedset-thermostat

TDQS

A3.8/5.0

Scored across 11 tools

Disambiguation5/5

Each tool targets a clearly distinct resource or action: dashboard read, standalone URL creation, action preparation, arm, disarm, lock, light, thermostat, alerts, audit history, and camera snapshot. The descriptions differentiate similar-sounding tools like adt-dashboard and open-standalone-dashboard, and the prepare-security-action gating makes mutation tools unambiguous.

Naming Consistency4/5

All names are kebab-case and mostly follow a verb_noun pattern (arm-system, control-lock, get-alerts, set-thermostat). Minor deviations include adt-dashboard (noun-only) and open-standalone-dashboard (extra adjective), but the overall convention is predictable.

Tool Count5/5

11 tools are well-scoped for an ADT security server: they cover state reading, action preparation, and mutations across panels, locks, lights, and thermostat, plus alerts, history, and camera. No obvious redundancy or missing tool class.

Completeness4/5

Core security operations (arm/disarm, lock, light, thermostat, alerts, camera, state read) are covered, with a safe prepare-then-mutate workflow. Minor gaps include no explicit device list, user management, or provider event history beyond current alerts, but adt-dashboard and get-alerts provide reasonable workarounds.

Maintenance

ActivityMaintained
ResponsivenessNo issues

Related MCP Connectors

Related MCP Servers

  • A
    license
    A
    quality
    A
    maintenance
    MCP server for SimpliSafe home security. Enables checking system status, sensors, events, arming/disarming, and controlling smart locks.
    10
    813 npm
    MIT
  • A
    license
    Not graded
    quality
    A
    maintenance
    Enables secure, auditable access to Home Assistant through MCP, with a read-only observer profile and an operator profile for controlled mutations.
    2
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Central MCP gateway for smart home automation, enabling agents to safely control Home Assistant and Node-RED with identity-based access, human confirmation for writes, and a WebUI for governance.
    1
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    MCP server for Hubitat Elevation hubs that controls devices via the Maker API, with optional gated access to undocumented admin routes, supporting device listing, command sending, virtual device and hub variable automation for Rule Machine, and hub management features.
    8
    MIT