Skip to main content
Glama
Mipiti
by Mipiti

Create Proposal

create_proposal

Raise a proposal to change a threat model's scope or design, including components, attacker positions, assets, or assumptions. It records the change for review instead of editing the model directly.

Instructions

Raise a proposal to change a model's scope or design. Call this when the code or your analysis says the model should gain or lose a component, or that an attacker position or asset should be removed by design; do not edit the model directly for those changes. Mutating: persists a proposal record.

A proposal is a change of scope or design. Raising one is not deciding it: a person (or an agent under a delegation rule that names the decision) decides it with decide_proposal. Design changes are never applied automatically. Poll list_proposals for the outcome.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
kindYesOne of ``add_component`` (payload ``{name, repo_url?, path?, trust_boundary_ids?}``), ``remove_component`` (payload ``{component_id}``), ``design_change`` (payload ``{target_kind: "attacker"|"asset", target_id, design_move}``; take ``design_move`` from ``get_design_leverage``), ``assumption`` (payload ``{co_id, group_id, precondition, assumption_id?, gap?}``: a precondition about the environment that only something outside this system can meet, one declarative sentence; ``assumption_id`` names an existing assumption that states it). A precondition a person already rejected for that objective is refused.
payloadYesJSON object string with the fields for ``kind``.
evidenceNoOptional JSON object string, e.g. ``{paths: [], symbols: [], note: ""}``, pointing at what you saw.
model_idYesID of the threat model.
rationaleYesWhy this change is right (what in the code or design supports it).
server_versionYes

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault

No arguments

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed1 schema field changedv0.83.1
    • changedInput schema / properties / kind / description
      Previous value: -"One of ``add_component`` (payload ``{name, repo_url?, path?,\ntrust_boundary_ids?}``), ``remove_component`` (payload\n``{component_id}``), ``design_change`` (payload ``{target_kind:\n\"attacker\"|\"asset\", target_id, design_move}``; take ``design_move``\nfrom ``get_design_leverage``)."New value: +"One of ``add_component`` (payload ``{name, repo_url?, path?,\ntrust_boundary_ids?}``), ``remove_component`` (payload\n``{component_id}``), ``design_change`` (payload ``{target_kind:\n\"attacker\"|\"asset\", target_id, design_move}``; take ``design_move``\nfrom ``get_design_leverage``), ``assumption`` (payload ``{co_id,\ngroup_id, precondition, assumption_id?, gap?}``: a precondition\nabout the environment that only something outside this system\ncan meet, one declarative sentence; ``assumption_id`` names an\nexisting assumption that states it). A precondition a person\nalready rejected for that objective is refused."
  2. Addedv0.75.0

TDQS

A4.4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the disclosure burden and does so well: it states this is mutating ('persists a proposal record'), that raising is not deciding, that design changes are never applied automatically, and that a person or delegated agent decides via decide_proposal. It stops short of stating explicit auth/permission requirements or any limits, so it is strong but not exhaustive.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two compact paragraphs, front-loaded with the action and the trigger condition, then the lifecycle note. Every sentence earns its place; the only minor cost is slight repetition between 'Raise a proposal...' and 'A proposal is a change of scope or design.'

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

An output schema exists, so return values need not be explained, and the description covers the workflow end-to-end: what the tool does, when to call it, that it is not the decision step, that changes are not auto-applied, and how to poll for the outcome. Nothing an agent needs to call it correctly is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 83%, so the schema already documents kind, payload, evidence, model_id, rationale and their formats (including the per-kind payload shapes). The description adds conceptual framing for what a proposal is but no syntax or constraint detail beyond the schema, so the baseline 3 is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb+resource ('Raise a proposal to change a model's scope or design') and explicitly scopes the kinds of changes covered (gain/lose a component, remove an attacker position or asset). It also distinguishes itself from direct model editing and from the decision step, so an agent can place it among siblings like decide_proposal and list_proposals.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives explicit when-to-use triggers ('when the code or your analysis says the model should gain or lose a component...'), an explicit when-not ('do not edit the model directly for those changes'), and names the alternatives for the follow-up step (decide_proposal, list_proposals). This is the full when/when-not/alternative triad.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Deploy Server

Other Tools