Skip to main content
Glama
GigantesHJI

securedact-mcp

securedact_read_file

Read-onlyIdempotent

Read a local file and return sanitized text with PII and secrets removed. Block path traversal, binary, and oversized content before forwarding to external AI.

Instructions

Safely read a local file and return only its sanitized (PII/secrets removed) text.

Use this when you must ingest a local file's contents for use with an external AI but want path-traversal, size, and binary defenses plus sanitization applied first. If the content is already in memory, use prepare_for_external_ai; for a sanitized file on disk, use create_safe_copy.

Side effects: reads a file from local disk and never transmits it. Sensitive paths and escapes are blocked before any file content is read. The returned 'sanitized_text' is safe to forward.

Returns a JSON object with 'status' ('ok' or 'blocked'), 'path', and 'sanitized_text' (present only when approved).

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
pathYesLocal filesystem path to read. It is resolved and defended against path traversal, symlink/UNC escapes, and oversized or binary content (FW-011/012/013); sensitive paths are blocked before any file content is read.
policyNoNamed redaction policy applied to the file contents. Defaults to 'strict_external_ai'. An unknown name returns a policy_not_found error.strict_external_ai
max_bytesNoOptional cap on the number of bytes read from the file. When omitted, the engine's configured size limit applies.

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault

No arguments

Schema Changelog

Changes observed during successful MCP inspections.

  1. Addedv0.4.2

TDQS

A4.4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint=true, idempotentHint=true, destructiveHint=false. The description adds useful context beyond those: side effects ('reads a file from local disk and never transmits it'), defense ordering ('Sensitive paths and escapes are blocked before any file content is read'), and return safety ('sanitized_text is safe to forward'). This aligns with and complements the annotations.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is front-loaded with the core purpose, then usage guidance, then side effects. It is moderately sized and each sentence earns its place, though the three-paragraph structure could be tightened slightly without losing information.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

There is an output schema, and the description still gives a concise summary of return fields (status, path, sanitized_text) and edge cases (blocked/ok). It covers when to use the tool, alternatives, side effects, and defense guarantees. With schema and annotations carrying the rest, nothing an agent needs to invoke or react to this tool correctly is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, with each parameter (path, policy, max_bytes) already described with details about defenses and defaults. The description adds no additional parameter-level semantics, so the baseline of 3 is appropriate—it doesn't degrade or enhance schema-provided meaning.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a specific verb+resource: 'Safely read a local file and return only its sanitized (PII/secrets removed) text.' It explicitly differentiates from siblings by naming prepare_for_external_ai and create_safe_copy, so an agent can distinguish it without opening schemas.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It gives explicit when-to-use: 'Use this when you must ingest a local file's contents for use with an external AI but want path-traversal, size, and binary defenses plus sanitization applied first.' It also provides concrete when-not and alternatives: 'If the content is already in memory, use prepare_for_external_ai; for a sanitized file on disk, use create_safe_copy.'

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.