Skip to main content
Glama
GigantesHJI

securedact-mcp

analyze_text

Read-onlyIdempotent

Inspect text locally to detect PII, secrets, and credentials, returning counts and optional findings without modifying or transmitting the original.

Instructions

Inspect text locally and report detected sensitive content without producing sanitized output.

Use this when you need to understand what PII, secrets, or credentials are present (counts, entity types, and, with review/debug modes, positions) but do not need redacted text for transmission. The original text is not modified and no sanitized representation is returned. For a policy-approved, ready-to-send result use prepare_for_external_ai; for a sanitized file use create_safe_copy; for reversing a prior local session use restore_text.

Returns a JSON object with 'status' ('ok', 'review_required', or 'blocked'), 'policy', 'policy_version', 'policy_digest', 'counts' (entity-type tallies), and, when response_mode is 'review' or 'debug', a 'findings' list. 'debug' additionally returns 'debug_details'.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
textYesFree text to inspect locally for sensitive content. Processing is on this machine only; the original text is never modified or transmitted.
policyNoNamed analysis policy controlling which detectors and entity types apply. Defaults to 'default'. Common values include 'default'; other policies may be registered in your environment. An unknown name returns a policy_not_found error.default
response_modeNoLevel of detail returned. 'minimal' returns only status and entity-type counts; 'review' additionally returns a 'findings' list with spans and entity types; 'debug' additionally returns 'debug_details' (only when debug responses are enabled). Defaults to 'minimal'.minimal

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault

No arguments

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed3 schema fields changedv0.4.2
    • addedInput schema / properties / policy / description
      Added value: +"Named analysis policy controlling which detectors and entity types apply. Defaults to 'default'. Common values include 'default'; other policies may be registered in your environment. An unknown name returns a policy_not_found error."
    • addedInput schema / properties / response_mode / description
      Added value: +"Level of detail returned. 'minimal' returns only status and entity-type counts; 'review' additionally returns a 'findings' list with spans and entity types; 'debug' additionally returns 'debug_details' (only when debug responses are enabled). Defaults to 'minimal'."
    • addedInput schema / properties / text / description
      Added value: +"Free text to inspect locally for sensitive content. Processing is on this machine only; the original text is never modified or transmitted."
  2. Changed1 schema field changedv0.2.0
    • addedInput schema / properties / response_mode
      Added value: +{
      +  "default": "minimal",
      +  "title": "Response Mode",
      +  "type": "string"
      +}
  3. First observedv0.1.0

TDQS

A4.9/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already mark the tool read-only and idempotent, and the description adds valuable context: the original text is not modified, no sanitized representation is returned, processing is local, and response modes change the output. No contradiction with annotations.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is well-structured into overview, usage guidance, and return contract. It is slightly longer than minimal but every sentence earns its place, and the core purpose is front-loaded.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a read-only analysis tool, the description is complete: it covers what it does, when to use it, alternatives, side-effect behavior, response modes, and return shape. The output schema also exists, so the description does not need to over-explain returns.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the baseline is 3. The description adds extra value by clarifying response_mode behavior and the policy_not_found error case, going beyond the schema without repeating it.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description opens with a specific verb and resource: 'Inspect text locally and report detected sensitive content without producing sanitized output.' This immediately distinguishes it from redaction/export tools and makes the tool's purpose unmistakable.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It explicitly says when to use the tool ('when you need to understand what PII, secrets, or credentials are present... but do not need redacted text') and names alternatives for other needs: prepare_for_external_ai, create_safe_copy, and restore_text. This gives an agent clear routing guidance.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.