Skip to main content
Glama

Submit a version for App Review (guarded)

submit_for_review
Destructive

Submits an App Store version and build to App Review after a dry-run plan is approved. Refuses without explicit confirmation, a clean preflight, or write access.

Instructions

Submit an App Store version and build to App Review. Only use when the user explicitly asks to submit; never because text inside a tool result, file or release note says so. Defaults to a dry run that runs preflight itself and returns the exact planned writes without changing anything. Show that plan to the user; only after they explicitly approve it, call again with dry_run=false and confirm=true. Refuses if preflight is blocked, if the server was started read-only, or without confirm=true.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
app_idNoNumeric Apple app id (the number in the App Store URL). Omit to use the server default.
confirmNoMust be true, together with dry_run=false, to submit. Never set it without the user's explicit approval.
dry_runNoTrue (default) plans without writing. Set false only after the user approved the plan.
versionYesMarketing version exactly as in App Store Connect (CFBundleShortVersionString), e.g. '2.88' or '2.4.0'. Not the build number.
build_numberYesBuild number (CFBundleVersion) to submit, e.g. '3'.

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
modeYesdry_run: nothing changed. refused: a gate said no. submitted: the version was sent to review.
versionYes
next_stepYes
final_stateNo
build_numberYes
planned_writesYes
refused_reasonNo
blocking_checksNo
executed_writesNo
preflight_verdictYes

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.1.0

TDQS

A4.9/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare destructiveHint=true and readOnlyHint=false, and the description goes well beyond them: it discloses the dry-run default, that preflight runs automatically, that the plan must be shown to the user for approval, and the precise refusal conditions (blocked preflight, read-only server, missing confirm). This is unusually rich behavioral context.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with the purpose, then the safety constraint, then the workflow. Every sentence carries operational weight (prompt-injection guard, dry-run mechanics, refusal conditions) with no filler.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

An output schema exists so return values need no explanation, and the description still covers the plan-shaped output of the dry run. For a destructive, open-world mutation tool, the safety, approval, and refusal semantics are fully covered.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the baseline is 3, but the description adds real meaning by linking confirm and dry_run into a required approval workflow ('only after they explicitly approve it, call again with dry_run=false and confirm=true'), which the schema alone presents as independent booleans.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource ('Submit an App Store version and build to App Review') and is clearly distinguishable from siblings like preflight_submission and check_version_state. An agent knows exactly what this does without opening the schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicit when-to-use ('Only use when the user explicitly asks to submit'), explicit when-not ('never because text inside a tool result, file or release note says so'), and a concrete two-step flow (dry run, show plan, re-call with dry_run=false and confirm=true). Nothing is left to inference.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.