Skip to main content
Glama
MadameFabulous

Chainsaw MCP Server

Chainsaw: EVTX overview

chainsaw_analyse_evtx

Analyse EVTX files to summarise channel, provider, and event-ID coverage, showing missing metadata and parsing gaps for Windows event log triage.

Instructions

Summarise EVTX channel, provider and event-ID coverage, including missing metadata.

Runs native analysis and a streamed dump pass. The inline per_file list is a bounded preview; page handle for full files, coverage_handle for identity counts, and diagnostics.handle for all runner messages. Missing Channel in ETW is not evidence of corruption, and successful exit does not establish complete parsing.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
pathsYesEVTX files or directories under an allowed root.
skip_errorsNoContinue past unreadable files.

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.1.0

TDQS

A3.9/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations give a partial profile (readOnlyHint=false, destructiveHint=false, idempotentHint=false, openWorldHint=false), and the description adds real behavior: it runs both a native analysis and a streamed dump pass, the per_file list is bounded, and full output arrives through page/coverage/diagnostics handles. The caveats that missing Channel is not corruption and that exit success does not prove complete parsing are genuinely valuable epistemic context beyond the annotations.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with the core summary in sentence one, followed by tightly packed supporting facts about passes, handles and caveats. No padding, though the handle enumeration in the middle sentence is dense and slightly list-like.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the description carries the return-value burden and does so by naming the per_file preview plus the page, coverage_handle and diagnostics.handle channels. It also warns about the limits of the result (bounded preview, missing Channel not meaning corruption, exit code not proving full parsing). Missing only explicit guidance on when to prefer this over sibling analysis tools.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100% for both parameters (paths, skip_errors), so the schema carries the parameter burden and a baseline 3 is appropriate. The description adds nothing about path constraints or the meaning of skip_errors beyond what the schema already documents.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb (Summarise) and resource (EVTX channel, provider and event-ID coverage), which cleanly separates it from siblings like chainsaw_analyse_shimcache, chainsaw_analyse_srum and chainsaw_analyse_gaps. An agent can tell what output domain this covers without opening the schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Usage is only implied by the word 'overview' — the description never states when to reach for this versus chainsaw_hunt, chainsaw_analyse_gaps or chainsaw_dump. It does clarify that the inline list is a bounded preview and that full data is fetched via handles, which is useful but not a when-to-use rule.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.