Skip to main content
Glama
Mipiti
by Mipiti

Revalidate Entity Quality

revalidate_entity_quality

Re-run quality validation on a threat model's existing assets and attackers to clear stale warnings or apply improvements without regenerating the model.

Instructions

Re-run quality validation on a threat model's existing assets and attackers, as if they were freshly generated. A fast first-pass check judges every entity; only the ones it flags get a deeper review that confirms them, sharpens their wording, or flags them for you.

Use this to apply validation improvements to an already-generated model, or to clear stale quality warnings — without regenerating the whole model (which would destroy controls, assertions, and components). It is non-destructive: an entity that should be removed is left in place with a quality warning rather than deleted, so no control objective loses its asset or attacker anchor. It creates no new model version: the re-validation is queued and runs in the background, and the refreshed warnings appear on the next read of the model.

May consume credits for the entities that need the deeper review; a model already in good shape costs nothing. Returns at once with {"accepted": true, "queued": <entities queued>, "model": {...}}, where model is the model as it stands before the re-validation lands.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
model_idYesID of the threat model whose assets and attackers to re-validate.
server_versionYes

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault

No arguments

Schema Changelog

Changes observed during successful MCP inspections.

  1. Addedv0.68.2

TDQS

A4.6/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the full burden and does so thoroughly: non-destructive (flagged entities are kept with a warning rather than deleted), no new model version, queued background execution, credit consumption conditional on entity count, and the exact synchronous return shape. Nothing about side effects is left to inference.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with the core action, then constraints, then cost, then return shape. Every sentence carries distinct information, though the description runs long and could trim slightly without loss.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Despite an output schema existing, the description still summarizes the return contract, and it covers the non-obvious traits (destructive-free behavior, async queue, credit cost) an agent needs before invoking. Complete for a background re-validation tool.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 50% (model_id documented, server_version undocumented). The description adds the semantic scope of model_id ('whose assets and attackers to re-validate') but says nothing about server_version. Baseline 3 is appropriate given the schema handles the main parameter.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource ('re-run quality validation on a threat model's existing assets and attackers') and describes the two-stage check (fast first pass, deeper review for flagged entities). An agent can distinguish it from regenerate_controls or refine_threat_model without opening schemas.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly names when to use it ('apply validation improvements to an already-generated model, or clear stale quality warnings') and the alternative it is not ('without regenerating the whole model, which would destroy controls, assertions, and components'). This is textbook when/when-not guidance.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Deploy Server

Other Tools