asset_mark_vuln
Assign a remediation status to a vulnerability by ID, enabling clear tracking of penetration testing findings.
Instructions
Mark a vulnerability with a status.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| status | Yes | ||
| vuln_id | Yes |
Assign a remediation status to a vulnerability by ID, enabling clear tracking of penetration testing findings.
Mark a vulnerability with a status.
| Name | Required | Description | Default |
|---|---|---|---|
| status | Yes | ||
| vuln_id | Yes |
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full burden of disclosing side effects. It only says 'mark a vulnerability with a status,' but does not state whether the operation overwrites existing statuses, what status values are allowed, reversibility, or permissions required. This is insufficient for a mutation tool.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single sentence with no filler, effectively front-loading the core action. While extremely terse, every word adds value. It is appropriately sized for the simple concept, though it sacrifices detail for brevity.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the lack of output schema and annotations, the description is not complete enough. It omits critical context such as allowed status values, the meaning of vuln_id in the asset context, and any behavioral effects. Sibling tools like asset_list_vulnerabilities imply a broader workflow, but this description does not connect to it.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The schema has two parameters (status, vuln_id) with no descriptions, so schema coverage is 0%. The description adds no meaning beyond the parameter names; it does not explain valid status values or how vuln_id relates to a vulnerability. The description should compensate for the lack of schema detail but does not.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description uses the specific verb 'mark' and identifies the resource 'vulnerability' with the object 'status', clearly stating the tool's basic function. However, it does not differentiate from siblings like update_finding_status, and 'mark' is somewhat generic.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
No guidance is provided on when to use this tool versus alternatives. There is no mention of prerequisites, typical use cases, or exclusions, leaving the agent without context for choosing it over similar tools.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/Neeraj829784/kali-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server