Skip to main content
Glama
MarkAC007

mcp-server-scf

by MarkAC007

scf_list_controls

Read-only

List SCF security controls with filtering by domain, framework, or search. Get paginated results including IDs, titles, descriptions, and mapped frameworks.

Instructions

List SCF security controls from the reference catalog. Returns paginated controls with SCF ID, title, description, and mapped frameworks. Filter by domain, framework, or free-text search.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
limitNoPage size (1–100, default 25)
domainNoSCF domain code (e.g., 'GOV', 'AST', 'IAC') — obtain from scf_list_domains
offsetNoPagination offset — number of results to skip (default 0)
searchNoFree-text filter applied to control title and description
frameworkNoFramework slug (e.g., 'nist-800-53', 'iso-27001') — obtain from scf_list_frameworks
include_deprecatedNoInclude catalog rows deprecated by a later SCF version. Default false — the catalog answers with active rows only, and deprecated rows carry a lifecycle badge when included.

Schema Changelog

Changes observed during successful MCP inspections. Dates show when Glama detected each change.

  1. Changed1 schema field changedv2.1.0
    • addedInput schema / properties / include_deprecated
      Added value: +{
      +  "description": "Include catalog rows deprecated by a later SCF version. Default false — the catalog answers with active rows only, and deprecated rows carry a lifecycle badge when included.",
      +  "type": "boolean"
      +}
  2. First observedv1.7.0

TDQS

A4.2/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

The readOnlyHint annotation already establishes that this is a safe read operation. The description adds value by stating that results are paginated and include SCF ID, title, description, and mapped frameworks. It does not mention default deprecated-row exclusion or sort order, though include_deprecated is documented in the schema.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is two purposeful sentences with the main operation front-loaded. Every sentence adds useful information about what the tool returns and how to filter, with no filler or redundancy.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a read-only list tool with six optional parameters and no output schema, the description covers the core purpose, return fields, and filter dimensions. Some details like deprecated-row inclusion and pagination defaults are delegated to the schema, but the schema fully documents them, so no critical gap remains.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, with each parameter already documented including ranges, defaults, and source tools for domain and framework values. The description merely repeats 'filter by domain, framework, or free-text search' and does not add new meaning beyond the schema, so the baseline of 3 applies.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description uses a specific verb 'List' and resource 'SCF security controls from the reference catalog', clearly stating the operation and scope. It differentiates from siblings like scf_get_control (single control) and scf_list_scoped_controls (scoped controls) by describing catalog-level, paginated listing with mapped frameworks.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description provides clear context: list catalog controls, optionally filtered by domain, framework, or free-text search. It does not explicitly name alternatives or when to prefer scf_get_control or scf_list_scoped_controls, but the 'reference catalog' framing makes the intended use reasonably clear.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Install Server

Other Tools

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/MarkAC007/mcp-server-scf'

If you have feedback or need assistance with the MCP directory API, please join our Discord server