Skip to main content
Glama
Mipiti
by Mipiti

submit_attestation

Affirm that an external assumption holds by submitting attestation details with expiry, attestor, and evidence. Mitigate linked control objectives until the attestation expires.

Instructions

Record that a responsible party affirmed an assumption holds.

Only for external assumptions. Non-applicability assumptions require CI verification (submit assertions + run mipiti-verify) — manual attestation is rejected for them.

An assumption with a current attestation can mitigate linked COs. When the attestation expires, those COs become at-risk until re-attested or covered by controls.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
model_idYesID of the threat model.
statementNoWhat was attested.
expires_atNoISO 8601 expiry date (e.g., "2026-06-30T00:00:00Z").
attested_byNoWho is attesting (name, role, organization).
evidence_urlNoOptional link to supporting documentation.
assumption_idYesID of the assumption (e.g., "AS1").
server_versionYes

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault

No arguments

Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations provided, so description carries full burden. It discloses that attestations can mitigate linked COs and that expiration makes COs at-risk. It also mentions manual attestation is rejected for non-applicability assumptions. However, it doesn't mention idempotency, permissions, or rate limits.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Three sentences with no wasted words. Purpose is front-loaded, usage guideline follows, and behavioral consequence is provided last. Highly efficient and well-structured.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given 7 parameters and required fields, the description covers main functional aspects including restrictions and downstream effects. It could mention the purpose of the 'statement' parameter or default expiry behavior, but these are covered in the schema. Output schema exists but not needed to evaluate.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 86% (high), and the description adds no extra meaning beyond the schema's parameter descriptions. Parameters are already well-documented in the schema, so baseline 3 is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool records an affirmation for an assumption. It distinguishes between external and non-applicability assumptions, referencing sibling tools submit_assertions and the verification process, which differentiates it from other assumption-related tools.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly states when to use this tool (only for external assumptions) and when not (non-applicability assumptions require CI verification). Provides clear alternatives (submit assertions + run mipiti-verify) and explains the consequences of attestation expiration.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Install Server

Other Tools

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/Mipiti/mipiti-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server