Skip to main content
Glama
Mipiti
by Mipiti

Convert Assumption To Controls

convert_assumption_to_controls

Convert a violated or retired assumption into proposed controls: retire its linkage and propose control builds for uncovered COs, ready for review and authoring.

Instructions

Convert a violated or retired assumption to controls. Mutating.

Retires the assumption's CO linkage and, when any CO it covered is left with no control, proposes a control build for those COs: the result's proposal (null when nothing is owed) is started with start_control_build after review, and authors the controls then. Nothing is authored by this call. Use when an assumption is no longer valid and the system owner needs to implement controls instead.

Side effect on control-level linkage: this assumption is also removed from every assumption_groups entry on every control that referenced it. Any group left empty by the removal is dropped; a control's status is not changed, and a control left with no group is no longer backed by an assumption. Underlying assumptions are not deleted — only the linkages.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
model_idYesID of the threat model.
assumption_idYesID of the assumption to convert.
server_versionYes

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault

No arguments

Schema Changelog

Changes observed during successful MCP inspections.

  1. Addedv0.62.2
  2. Removedv0.62.0
  3. First observedv0.57.0

TDQS

A4.4/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the full burden and delivers extensively: it states nothing is authored here, describes the CO-linkage retirement, the proposal behavior (null when nothing owed), and detailed side effects on assumption_groups, including that empty groups are dropped, status is unchanged, and underlying assumptions are not deleted.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with the core action and mutability flag before the detail. The body is comparatively long but each sentence conveys a distinct behavioral fact (proposal handling, group side effects, non-deletion), so little is wasteful.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a complex mutating tool, it covers the operation, the deferred build workflow, and all linkage side effects thoroughly. An output schema exists, yet the description helpfully explains the key 'proposal' result field, leaving no material gap for correct invocation.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 67%; model_id and assumption_id are documented in the schema while server_version is not. The description adds no parameter-level syntax or format detail, so it does not fully compensate for the coverage gap, though the remaining params are largely self-explanatory.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb+resource ('Convert a violated or retired assumption to controls') and immediately flags its nature ('Mutating.'). It is clearly distinguishable from sibling tools like add_assumption, edit_assumption, and delete_assertion.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Provides explicit when-to-use guidance ('Use when an assumption is no longer valid and the system owner needs to implement controls instead') and directs the agent to the follow-up tool (start_control_build after review). It does not name when-not to use it or a direct alternative, but the context is clear.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Deploy Server

Other Tools