Skip to main content
Glama
Mipiti
by Mipiti

Add Asset

add_asset

Add a new asset to a threat model to capture protected data or resources and their security properties, creating a new version.

Instructions

Add a new asset to a threat model. Creates a new version.

Authoring contract: name the data or resource being protected and the security property at stake (Confidentiality / Integrity / Availability / Usage), not a mechanism or control ("per-organization key-wrapping material", not "KMS encryption"). An asset phrased as a mechanism is flagged with a quality_warning and yields under-specified control objectives. An asset that does not apply is recorded with a non-applicability assumption or create_co_disposition; there is no status to set.

The platform reasons the factor decomposition and composes impact with the prompt generation uses, so factors are calibrated alike; override one afterwards with edit_asset and a change_reason. component_ids links the asset to the deployable units that hold it, which feeds reachability (several for a multi-instance asset, e.g. a session token on client and cache).

A proposal matching a soft-deleted asset is gated: it either restores that asset (auto_restored: true, restored_asset_id, discarded_fields; its CO tombstones revive) or is refused as similar ({accepted: false, classification: "similar", candidate_restore_id}, nothing saved). A normal create returns {model, controls_carried, ...}. 503: an evaluator is unavailable, retry with backoff; 502: it answered malformed, retry.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
nameYesAsset name (required).
notesNoOptional notes.
model_idYesID of the threat model.
descriptionNoOptional description (recommended — feeds the factor-reasoning prompt).
component_idsNoComma-separated component IDs scoping the asset (e.g., "CMP1,CMP2"). Empty / omitted = unscoped. Validated against components declared on the model.
server_versionYes
security_propertiesNoComma-separated properties, e.g. "C,I,A" (default: "C").

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault

No arguments

Schema Changelog

Changes observed during successful MCP inspections.

  1. Addedv0.62.2
  2. Removedv0.62.1
  3. First observedv0.57.0

TDQS

A4.6/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the full burden and does so richly: it discloses the versioning side effect, quality_warning flagging for mechanism-phrased assets, the soft-deleted-asset gating behavior (auto_restored, restored_asset_id, discarded_fields, or a {accepted: false, classification: "similar"} refusal), and 503/502 retry semantics. This is behavior an agent cannot infer from the schema.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The purpose is front-loaded and the contract/error details are organized under clear paragraphs. It is dense and fairly long, with a couple of asides (e.g., the factor-decomposition rationale) that could be trimmed, but nearly every sentence carries actionable information.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a 7-parameter mutation tool with an output schema, the description covers the mutation contract, the authoring requirement, edge cases (soft-deleted matches), and error/retry behavior. An output schema exists, so its decision to also sketch return shapes is a bonus rather than a gap.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 86%, so the schema already documents most parameters and the baseline is 3. The description adds meaning beyond the schema by explaining that component_ids 'feeds reachability' for multi-instance assets, and by giving the authoring contract that shapes what 'name' should contain. That is genuine added value, though it doesn't cover every parameter.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The first sentence gives a specific verb+resource ('Add a new asset to a threat model') and immediately notes the side effect ('Creates a new version'). It also routes the agent to the sibling edit_asset for post-hoc changes, so the tool is distinguishable from its nearest neighbor without opening a schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description gives clear context on when to use this tool (creating a new asset, and using create_co_disposition / non-applicability assumptions when an asset doesn't apply) and explicitly names edit_asset for overrides. It stops short of an explicit 'use add_asset when X, not when Y' clause, so a 4 rather than a 5.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Deploy Server

Other Tools